cbcvebase.
CVE-2021-31164
published 2021-05-04

CVE-2021-31164: Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheunomi< 1.5.51.5.5
apache_software_foundationapache_unomi>= Apache Unomi < 1.5.51.5.5