Medium severity4.3NVD Advisory· Published Jan 10, 2022· Updated Jun 17, 2026
CVE-2021-22060
CVE-2021-22060
Description
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework:spring-coreMaven | >= 5.3.0, < 5.3.14 | 5.3.14 |
org.springframework:spring-coreMaven | >= 5.2.0, < 5.2.19 | 5.2.19 |
Affected products
5- cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.15.0:*:*:*:*:*:*:*
- Spring/Spring Frameworkdescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-6gf2-pvqw-37phghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-22060ghsaADVISORY
- tanzu.vmware.com/security/cve-2021-22060nvdVendor AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.