Описание
Heron allows CRLF log injection
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
Пакеты
Наименование
org.apache.heron:heron-api
maven
Затронутые версииВерсия исправления
< 0.20.5-incubating
0.20.5-incubating
Связанные уязвимости
CVSS3: 9.8
nvd
больше 3 лет назад
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.