In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: vmware
Published: 2022-01-07T22:39:55
Updated: 2024-08-03T18:30:23.916Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-22060
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-01-10T14:10:16.680
Modified: 2022-05-13T15:52:15.253
Link: CVE-2021-22060
Redhat