Input Validation Vulnerability in Spring Framework by VMware
CVE-2021-22060
4.3MEDIUM
Summary
The Spring Framework showcases a vulnerability where malicious input can lead to the insertion of unintended log entries. This issue arises in versions 5.3.0 through 5.3.13, as well as 5.2.0 through 5.2.18, and affects legacy versions too. It serves as an extension of previous vulnerabilities by enhancing safeguards against various input types within the codebase. Addressing this vulnerability is critical for maintaining the integrity of logging mechanisms and ensuring the application's overall security.
Affected Version(s)
Spring Framework Spring Framework 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved