VulnerabilityModified
CVE-2021-43410
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements.
MEDIUM 5.3EPSS 2.39%
Does this matter?
Lower severity and a low EPSS score (2.39%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1] https://github.com/apache/airavata-django-portal/commit/3c5d8c72bfc3eb0af8693a655a5d60f9273f8170
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 2.39% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-117, CWE-116
- Affected
- apache/airavata django portal
- Source
- security@apache.org
References
- https://lists.apache.org/thread/q64h16ofdxk29soz3jj561nysnzcrl31Mailing List, Vendor Advisory
- https://lists.apache.org/thread/q64h16ofdxk29soz3jj561nysnzcrl31Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.