ZeroHour

CVE-2021-31164

CVSS 3.1
7.5 high
EPSS
2%p82
Published
()
Modified
Description

Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

Vendors
apache
Products
unomi
Weakness
CWE-93, CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.