Loading HuntDB...

GHSA-6gf2-pvqw-37ph

GitHub Security Advisory

Log entry injection in Spring Framework

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

Affected Packages

Maven org.springframework:spring-core
Affected versions: 5.3.0 (fixed in 5.3.14)
Maven org.springframework:spring-core
Affected versions: 5.2.0 (fixed in 5.2.19)

Related CVEs

Key Information

GHSA ID
GHSA-6gf2-pvqw-37ph
Published
January 12, 2022 11:04 PM
Last Modified
January 18, 2022 10:38 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.springframework:spring-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 29, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.