GHSA-95w5-q9vp-5vrm
CRITICALCVE-2021-42010Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
- Affected
- < 0.20.5-incubating
- Fixed in
- 0.20.5-incubating
- Published
- 2022-10-24
- Source
- github