Vulnerabilities > CVE-2021-22096
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
Vulnerable Configurations
References
- https://security.netapp.com/advisory/ntap-20211125-0005/
- https://security.netapp.com/advisory/ntap-20211125-0005/
- https://tanzu.vmware.com/security/cve-2021-22096
- https://tanzu.vmware.com/security/cve-2021-22096
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html