You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@sling.apache.org by Robert Munteanu <ro...@apache.org> on 2022/06/22 07:15:42 UTC

CVE-2022-32549: Apache Sling: log injection in Sling logging

Severity: important

Description:

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

Credit:

Apache Sling would like to thank Alex Collignon for reporting this issue.