Bug 701867 - ehcache: log file CRLF injection
Summary: ehcache: log file CRLF injection
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: All
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-05-04 06:26 UTC by David Jorm
Modified: 2019-09-29 12:44 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-06-21 02:33:41 UTC


Attachments (Terms of Use)

Description David Jorm 2011-05-04 06:26:10 UTC
The ehcache component is used by hibernate to provide caching. A potential log file CRLF injection vulnerability has been identified in ehcache. A bug is open against the upstream project:

https://jira.terracotta.org/jira/browse/EHC-854

Comment 3 David Jorm 2011-06-21 02:33:41 UTC
The upstream bug has been closed as WONTFIX, saying that the logging framework should handle sanitization. Our developers have confirmed that no Red Hat products parse or process ehcache logs, significantly lowering the impact of this bug. Given upstream won't fix it, and the impact on Red Hat products is negligible, this tracker is being closed.


Note You need to log in before you can comment on or make changes to this bug.