Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0zNDJjLWY4NjktNW00NM4AAfo7

Apache Sling POST Servlets Denial of Service Vulnerability

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.

Permalink: https://github.com/advisories/GHSA-342c-f869-5m44
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zNDJjLWY4NjktNW00NM4AAfo7
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 8 months ago


Identifiers: GHSA-342c-f869-5m44, CVE-2012-2138
References: Repository: https://github.com/apache/sling-org-apache-sling-servlets-post
Blast Radius: 0.0

Affected Packages

maven:org.apache.sling:org.apache.sling.servlets.post
Dependent packages: 84
Dependent repositories: 676
Downloads:
Affected Version Ranges: < 2.1.2
Fixed in: 2.1.2
All affected versions: 2.1.0
All unaffected versions: 2.1.2, 2.2.0, 2.3.0, 2.3.2, 2.3.4, 2.3.6, 2.3.8, 2.3.10, 2.3.12, 2.3.14, 2.3.16, 2.3.18, 2.3.20, 2.3.22, 2.3.24, 2.3.26, 2.3.28, 2.3.30, 2.3.32, 2.3.34, 2.3.36, 2.4.2, 2.4.4, 2.4.6, 2.5.0, 2.6.0