[MAVEN:GHSA-95W5-Q9VP-5VRM] Heron allows CRLF log injection

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.

Package Affected Version
pkg:maven/org.apache.heron/heron-api < 0.20.5-incubating
Package Fixed Version
pkg:maven/org.apache.heron/heron-api = 0.20.5-incubating
ID
MAVEN:GHSA-95W5-Q9VP-5VRM
Severity
critical
URL
https://github.com/advisories/GHSA-95w5-q9vp-5vrm
Published
2022-10-24T19:00:16
(23 months ago)
Modified
2023-08-17T05:02:40
(13 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.heron/heron-api org.apache.heron heron-api < 0.20.5-incubating
Fixed pkg:maven/org.apache.heron/heron-api org.apache.heron heron-api = 0.20.5-incubating
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...