Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
2022-10-24T14:15:49.560
2025-05-07T16:15:19.423
Modified
CVSSv3.1: 9.8 (CRITICAL)