CVE-2021-22096: Medium severity VMware Spring Framework vulnerability
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-22096?
CVE-2021-22096 is a vulnerability in the Spring Framework that allows a remote attacker to bypass security restrictions and insert additional log entries.
What versions of the Spring Framework are affected by CVE-2021-22096?
Versions 5.3.0 - 5.3.10 and 5.2.0 - 5.2.17 of the Spring Framework are affected.
How can an attacker exploit CVE-2021-22096?
An attacker can exploit CVE-2021-22096 by sending a specially-crafted input to bypass security restrictions and insert additional log entries.
What is the severity of CVE-2021-22096?
CVE-2021-22096 has a severity rating of medium.
Where can I find more information about CVE-2021-22096?
You can find more information about CVE-2021-22096 on the VMware Security Advisory, Red Hat Bugzilla, and Red Hat Errata websites.