[MAVEN:GHSA-6GF2-PVQW-37PH] Log entry injection in Spring Framework

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

Package Affected Version
pkg:maven/org.springframework/spring-core >= 5.2.0, < 5.2.19
pkg:maven/org.springframework/spring-core >= 5.3.0, < 5.3.14
ID
MAVEN:GHSA-6GF2-PVQW-37PH
Severity
moderate
URL
https://github.com/advisories/GHSA-6gf2-pvqw-37ph
Published
2022-01-12T23:04:06
(2 years ago)
Modified
2023-02-03T05:04:29
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.springframework/spring-core org.springframework spring-core >= 5.2.0 < 5.2.19
Fixed pkg:maven/org.springframework/spring-core org.springframework spring-core = 5.2.19
Affected pkg:maven/org.springframework/spring-core org.springframework spring-core >= 5.3.0 < 5.3.14
Fixed pkg:maven/org.springframework/spring-core org.springframework spring-core = 5.3.14
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...