Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22060

Опубликовано: 10 янв. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7springframeworkNot affected
Red Hat JBoss BRMS 5springframeworkOut of support scope
Red Hat JBoss Data Virtualization 6springframeworkOut of support scope
Red Hat JBoss Fuse 6springframeworkOut of support scope
Red Hat JBoss Fuse Service Works 6springframeworkOut of support scope
Red Hat JBoss SOA Platform 5springframeworkOut of support scope
Red Hat Process Automation 7springframeworkNot affected
Red Hat Virtualization 4rhvm-dependenciesNot affected
Red Hat Fuse 7.11springframeworkFixedRHSA-2022:553207.07.2022

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2055480springframework: Additional Log Injection in Spring Framework (follow-up to CVE-2021-22096)

EPSS

Процентиль: 45%
0.00223
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
nvd
больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
debian
больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older ...

CVSS3: 4.3
github
больше 3 лет назад

Log entry injection in Spring Framework

EPSS

Процентиль: 45%
0.00223
Низкий

4.3 Medium

CVSS3