{"id":"CVE-2021-22060","aliases":["GHSA-6gf2-pvqw-37ph"],"url":"https://o3.security/vulnerability/CVE-2021-22060","summary":"Log entry injection in Spring Framework","details":"In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.","published":"2022-01-10T14:10:16.680Z","modified":"2026-07-08T05:57:31.070638557Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},"epss":{"score":0.00855,"percentile":0.55194,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework:spring-core","fixedVersion":"5.3.14"},{"ecosystem":"Maven","name":"org.springframework:spring-core","fixedVersion":"5.2.19"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://tanzu.vmware.com/security/cve-2021-22060"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22060"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:57:31.070638557Z"}}