PT-2021-19198 · Apache · Apache Unomi

Christos Mathas

+1

·

Published

2021-05-04

·

Updated

2022-10-25

·

CVE-2021-31164

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Unomi versions prior to 1.5.5
Description The issue is related to CRLF log injection due to the lack of escaping in log statements.
Recommendations For versions prior to 1.5.5, update to version 1.5.5 or later to resolve the issue.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-31164
GHSA-RM7F-MPCJ-W4F6

Affected Products

Apache Unomi