Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gf2-pvqw-37ph

Опубликовано: 12 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Log entry injection in Spring Framework

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

Пакеты

Наименование

org.springframework:spring-core

maven
Затронутые версииВерсия исправления

>= 5.3.0, < 5.3.14

5.3.14

Наименование

org.springframework:spring-core

maven
Затронутые версииВерсия исправления

>= 5.2.0, < 5.2.19

5.2.19

EPSS

Процентиль: 45%
0.00223
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
redhat
больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
nvd
больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
debian
больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older ...

EPSS

Процентиль: 45%
0.00223
Низкий

4.3 Medium

CVSS3