micrometer-core is vulnerable to Improper Neutralization of Special Elements
59
Medium Risk
micrometer-core and micrometer-registry-statsd do not sanitize newline characters in metric names and tags. Untrusted metric input can inject extra StatsD lines or log lines, spoofing metrics and polluting logs. This is exploitable when applications put untrusted data into meters, which instrumentation should not do. The patch strips CR and LF from metric names and tags.
You are affected if you are using a version that falls within the vulnerable range and untrusted input is used as metric names, tag keys, or tag values for StatsD or LoggingMeterRegistry.
micrometer-core is vulnerable to Improper Neutralization of Special Elements in versions 0.0.1 - 1.16.6 and 1.17.0 - 1.17.0.
Upgrade the io.micrometer:micrometer-core and/or the io.micrometer:micrometer-registry-statsd library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant