Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
Users of affected versions should apply the following mitigation. 5.3.x users should upgrade to 5.3.14+. 5.2.x users should upgrade to 5.2.19+. No other steps are necessary. Releases that have fixed this issue include:
This vulnerability was responsibly reported by psytester.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy