Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22096

Опубликовано: 28 окт. 2021
Источник: redhat
CVSS3: 4.3

Описание

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5springframeworkOut of support scope
Red Hat JBoss Data Virtualization 6springframeworkOut of support scope
Red Hat JBoss Fuse 6springframeworkOut of support scope
Red Hat JBoss Fuse Service Works 6springframeworkOut of support scope
Red Hat JBoss SOA Platform 5springframeworkOut of support scope
Red Hat Fuse 7.11springframeworkFixedRHSA-2022:553207.07.2022
Red Hat Virtualization Engine 4.4ovirt-dependenciesFixedRHSA-2022:555514.07.2022
Red Hat Virtualization Engine 4.4org.ovirt.engine-rootFixedRHSA-2022:639308.09.2022
RHDM 7.12.1springframeworkFixedRHSA-2022:111029.03.2022
RHPAM 7.12.1springframeworkFixedRHSA-2022:110829.03.2022

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2034584springframework: malicious input leads to insertion of additional log entries

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 4 года назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
nvd
почти 4 года назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
debian
почти 4 года назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older ...

CVSS3: 4.3
github
около 3 лет назад

Improper Output Neutralization for Logs in Spring Framework

4.3 Medium

CVSS3