CVE-2022-32549

Description

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
3.181

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-32549 are affected in Apache-org.apache.sling.api 2.25.0Windows
Vulnerabilities CVE-2022-32549 are affected in Apache - org.apache.sling.commons.log 5.4.0Windows
Vulnerabilities CVE-2022-32549 are affected in Apache-org.apache.sling.api for Linux 2.25.0Linux
Vulnerabilities CVE-2022-32549 are affected in Apache - org.apache.sling.commons.log for Linux 5.4.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234