ZeroHour

CVE-2021-22060

CVSS 3.1
4.3 medium
EPSS
<1%p56
Published
()
Modified
Description

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

Vendors
vmwareoracle
Products
spring framework, communications cloud native core console, communications cloud native core service communication proxy
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.