ZeroHour

CVE-2021-22096

CVSS 3.1
4.3 medium
EPSS
1%p70
Published
()
Modified
Description

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

Vendors
vmwarenetapporacle
Products
spring framework, active iq unified manager, management services for element software and netapp hci, metrocluster tiebreaker, snap creator framework, snapcenter, communications cloud native core console, communications cloud native core service communication proxy
Weakness
CWE-117
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.