github.com/labstack/echo/v4 is vulnerable to Improper Output Neutralization for Logs
42
Medium Risk
Affected versions of this package are vulnerable to JSON Log Injection via a Missing Character Escape in the logger middleware, where user-supplied input in HTTP requests is not properly escaped before being written to JSON-formatted logs. An attacker can exploit this by crafting malicious query parameters containing JSON special characters, such as commas and quotes, to inject arbitrary fields into the log output, falsifying log data by overwriting critical fields like method and remote_ip or by deliberately corrupting the JSON structure to disrupt log processing systems.
You are affected if you are using a version that falls within the vulnerable range.
github.com/labstack/echo/v4 is vulnerable to Improper Output Neutralization for Logs in versions 4.0.0 - 4.13.4.
Upgrade the github.com/labstack/echo/v4 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant