REDHAT-BUG-2034584: Low severity VMware Spring Framework vulnerability
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
References: https://tanzu.vmware.com/security/cve-2021-22096
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2034584?
The severity of REDHAT-BUG-2034584 is considered moderate due to the potential for log injection attacks.
How do I fix REDHAT-BUG-2034584?
To fix REDHAT-BUG-2034584, you should update Spring Framework to versions 5.3.11 or later, or 5.2.18 or later.
What versions of Spring Framework are affected by REDHAT-BUG-2034584?
REDHAT-BUG-2034584 affects Spring Framework versions 5.3.0 - 5.3.10 and 5.2.0 - 5.2.17.
What kind of attacks can REDHAT-BUG-2034584 lead to?
REDHAT-BUG-2034584 can lead to log injection attacks, allowing malicious input to create additional log entries.
Is REDHAT-BUG-2034584 fixed in the latest versions of Spring Framework?
Yes, REDHAT-BUG-2034584 is fixed in Spring Framework versions 5.3.11 and 5.2.18, among others.