{"id":"CVE-2021-31164","details":"Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.","aliases":["GHSA-rm7f-mpcj-w4f6"],"modified":"2026-07-09T01:30:52.171163Z","published":"2021-05-04T07:15:07.803Z","references":[{"type":"FIX","url":"http://unomi.apache.org/security/cve-2021-31164"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/unomi","events":[{"introduced":"0"},{"fixed":"b5bef98e3ccad8169d21a746fcc3e2017ef4997c"}],"database_specific":{"cpe":"cpe:2.3:a:apache:unomi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.5.5"}],"source":"CPE_RANGE"}}],"versions":["unomi-root-1.5.4","unomi-root-1.5.3","unomi-root-1.5.2","unomi-root-1.5.1","unomi-root-1.5.0","unomi-root-1.4.0","unomi-root-1.2.0-incubating","unomi-root-1.1.0-incubating","unomi-root-1.0.0-incubating"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31164.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}