Skip to main content

Improper Output Neutralization for Logs

CVE-2021-22096

Severity Medium
Score 4.3/10

Summary

In Spring Framework versions 5.3.0 through 5.3.11, 5.2.0 through 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-117 - Improper Output Neutralization for Logs

The software does not neutralize or incorrectly neutralizes output that is written to logs.

Advisory Timeline

  • Published