CVE-2021-31164

HIGH

Apache Unomi <1.5.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

Scores

CVSS v3 7.5
EPSS 0.0294
EPSS Percentile 86.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-93 CWE-74
Status published
Products (2)
apache/unomi < 1.5.5
org.apache.unomi/unomi 0 - 1.5.5Maven
Published May 04, 2021
Tracked Since Feb 18, 2026