Medium severity4.3NVD Advisory· Published Oct 28, 2021· Updated Jun 17, 2026
CVE-2021-22096
CVE-2021-22096
Description
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework:spring-coreMaven | >= 5.3.0, < 5.3.11 | 5.3.11 |
org.springframework:spring-coreMaven | >= 5.2.0, < 5.2.18 | 5.2.18 |
org.springframework:springMaven | >= 5.2.0, < 5.2.18 | 5.2.18 |
org.springframework:springMaven | >= 5.3.0, < 5.3.11 | 5.3.11 |
Affected products
13cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:metrocluster_tiebreaker:-:*:*:*:*:clustered_data_ontap:*:*
- cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.15.0:*:*:*:*:*:*:*
- Spring/Spring Frameworkdescription
- ghsa-coords2 versions
>= 5.2.0, < 5.2.18+ 1 more
- (no CPE)range: >= 5.2.0, < 5.2.18
- (no CPE)range: >= 5.3.0, < 5.3.11
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-rfmp-97jj-h8m6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-22096ghsaADVISORY
- security.netapp.com/advisory/ntap-20211125-0005/nvdThird Party Advisory
- tanzu.vmware.com/security/cve-2021-22096nvdVendor AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20211125-0005ghsaWEB
News mentions
0No linked articles in our index yet.