CVE-2021-22096
—CVSS 3.1
4.3 medium
EPSS
1%p70
Published
()
Modified
Description
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
- Vendors
- vmwarenetapporacle
- Products
- spring framework, active iq unified manager, management services for element software and netapp hci, metrocluster tiebreaker, snap creator framework, snapcenter, communications cloud native core console, communications cloud native core service communication proxy
- Weakness
- CWE-117
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.