|
Message-ID: <de7dfa60-f860-951d-5a58-8a60b7341b89@apache.org> Date: Sun, 23 Oct 2022 15:04:39 +0000 From: Josh Fischer <joshfischer@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2021-42010: Apache Heron (Incubating): CRLF log injection Severity: low Description: Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue. Credit: The Apache Heron (Incubating) project would like to thank Bo Yu for bringing this matter to our attention.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.