Description
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
Remediation
References
https://lists.apache.org/thread/j65nwr8n7jchngwqptzh100drcr4ry2q
http://www.openwall.com/lists/oss-security/2022/10/23/2
Related Vulnerabilities
CVE-2022-34790 Vulnerability in maven package org.jenkins-ci.plugins:xfpanel
CVE-2023-24977 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2016-7103 Vulnerability in maven package org.webjars:jquery-ui
CVE-2022-26885 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-server
CVE-2019-1003072 Vulnerability in maven package org.jenkins-ci.plugins:wildfly-deployer