CVE-2021-22060: Input Validation
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
Other sources
VMware Tanzu Spring Framework could allow a remote authenticated attacker to bypass security restrictions, caused by improper input validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to insert additional log entries.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22060?
CVE-2021-22060 is a vulnerability in the Spring Framework that allows a user to provide malicious input to cause the insertion of additional log entries.
What versions of Spring Framework are affected by CVE-2021-22060?
Versions 5.3.0 - 5.3.13 and 5.2.0 - 5.2.18 of the Spring Framework, as well as older unsupported versions, are affected by CVE-2021-22060.
What is the severity of CVE-2021-22060?
CVE-2021-22060 has a severity value of 4.3, which is considered medium.
How can I protect against CVE-2021-22060?
To protect against CVE-2021-22060, it is recommended to upgrade to a fixed version of Spring Framework.
Where can I find more information about CVE-2021-22060?
You can find more information about CVE-2021-22060 on the CVE (https://www.cve.org/CVERecord?id=CVE-2021-22060) and NVD (https://nvd.nist.gov/vuln/detail/CVE-2021-22060) websites.