CVE-2021-42010

Publication date

2022-10-24 00:00:00

Family

apache

State

PUBLISHED

Description

Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.