Improper Input Validation Affecting org.apache.sling:org.apache.sling.auth.core package, versions [,1.1.4)
Snyk CVSS
Attack Complexity
Low
User Interaction
Required
Threat Intelligence
EPSS
0.17% (54th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHESLING-30728
- published 9 Jun 2015
- disclosed 24 Oct 2013
- credit Unknown
Introduced: 24 Oct 2013
CVE-2013-4390 Open this link in a new tabOverview
org.apache.sling:org.apache.sling.auth.core
is a framework for RESTful web-applications based on an extensible content tree.
Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the resource parameter, related to "a custom login form and XSS."