CVE-2021-21234 is a directory traversal vulnerability in the spring-boot-actuator-logview library, affecting versions prior to 0.2.13. This flaw allows an authenticated attacker to access files outside the intended logging directory by manipulating the "base" parameter in the logview endpoint. Rated 7.7 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), it presents a high risk of unauthorized information disclosure with low attack complexity. While not currently on the CISA KEV list or showing active exploitation, Nuclei templates exist for this vulnerability, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.2.12CPE matchmatch criteria | cpe:2.3:a:spring-boot-actuator-logview_project:spring-boot-actuator-logview:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.