Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 Maven

Improper Output Neutralization for Logs in Spring Framework

GHSA-rfmp-97jj-h8m6 · CVE-2021-22096

Published · Modified

Description

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

Ready to move

Start Securing

Free, no credit card | First findings in minutes