Description
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1399 | Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. |
Github GHSA |
GHSA-rm7f-mpcj-w4f6 | Command injection in Apache Unomi |
References
| Link | Providers |
|---|---|
| http://unomi.apache.org/security/cve-2021-31164 |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T22:55:53.073Z
Reserved: 2021-04-14T00:00:00.000Z
Link: CVE-2021-31164
No data.
Status : Modified
Published: 2021-05-04T07:15:07.803
Modified: 2024-11-21T06:05:12.827
Link: CVE-2021-31164
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA