Input Validation Vulnerability in Spring Framework by VMware
CVE-2021-22060

4.3MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
10 January 2022

Summary

The Spring Framework showcases a vulnerability where malicious input can lead to the insertion of unintended log entries. This issue arises in versions 5.3.0 through 5.3.13, as well as 5.2.0 through 5.2.18, and affects legacy versions too. It serves as an extension of previous vulnerabilities by enhancing safeguards against various input types within the codebase. Addressing this vulnerability is critical for maintaining the integrity of logging mechanisms and ensuring the application's overall security.

Affected Version(s)

Spring Framework Spring Framework 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.