← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

No Active Exploit Signals
CVSS Base Score
4.3
MEDIUM
EPSS Probability:1.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-117 ↗CWE-117: Improper Output Neutralization for Logs

Affected Products & Versions

Vendor Product Affected Versions
vmware spring_framework all
netapp active_iq_unified_manager all
netapp management_services_for_element_software_and_netapp_hci all
netapp metrocluster_tiebreaker all
netapp snap_creator_framework all
netapp snapcenter all
oracle communications_cloud_native_core_console 1.9.0
oracle communications_cloud_native_core_service_communication_proxy 1.15.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.268%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVMware by Broadcom · Vendor · USA
Reserved2021-01-04T00:00:00
Published2021-10-28T15:22:35
Last Updated2024-08-03T18:30:23

LINK COPIED TO CLIPBOARD