AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-22060

MEDIUM · CVSS 4.3 EPSS 0.85%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-01-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-22060
Severity
MEDIUM
CVSS
4.3
EPSS
0.85%

Original NVD Description

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.