Heron allows CRLF log injection
Critical severity
GitHub Reviewed
Published
Oct 24, 2022
to the GitHub Advisory Database
•
Updated Aug 17, 2023
Package
Affected versions
< 0.20.5-incubating
Patched versions
0.20.5-incubating
Description
Published by the National Vulnerability Database
Oct 24, 2022
Published to the GitHub Advisory Database
Oct 24, 2022
Reviewed
Oct 25, 2022
Last updated
Aug 17, 2023
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
References