Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 23 Oct 2022 15:04:39 +0000
From: Josh Fischer <joshfischer@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2021-42010: Apache Heron (Incubating): CRLF log injection 

Severity: low

Description:

Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements.  Please update to version 0.20.5-incubating which addresses this issue. 

Credit:

The Apache Heron (Incubating) project would like to thank Bo Yu for bringing this matter to our attention.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.