[MAVEN:GHSA-6GF2-PVQW-37PH] Log entry injection in Spring Framework
Severity
Moderate
Affected Packages
2
Fixed Packages
2
CVEs
1
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
Package | Affected Version |
---|---|
pkg:maven/org.springframework/spring-core | >= 5.2.0, < 5.2.19 |
pkg:maven/org.springframework/spring-core | >= 5.3.0, < 5.3.14 |
Package | Fixed Version |
---|---|
pkg:maven/org.springframework/spring-core | = 5.2.19 |
pkg:maven/org.springframework/spring-core | = 5.3.14 |
- ID
- MAVEN:GHSA-6GF2-PVQW-37PH
- Severity
- moderate
- URL
- https://github.com/advisories/GHSA-6gf2-pvqw-37ph
- Published
-
2022-01-12T23:04:06
(2 years ago) - Modified
-
2023-02-03T05:04:29
(19 months ago) - Rights
- Maven Security Team
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:maven/org.springframework/spring-core | org.springframework | spring-core | >= 5.2.0 < 5.2.19 | |||
Fixed | pkg:maven/org.springframework/spring-core | org.springframework | spring-core | = 5.2.19 | |||
Affected | pkg:maven/org.springframework/spring-core | org.springframework | spring-core | >= 5.3.0 < 5.3.14 | |||
Fixed | pkg:maven/org.springframework/spring-core | org.springframework | spring-core | = 5.3.14 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |