Description:

The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher 
API resulting in a generic type of include-based cross-site scripting issues on 
the Apache Sling level. The vulnerability is exploitable by an attacker that is 
able to include a resource with specific content-type and control the include 
path (i.e. writing content). The impact of a successful attack is privilege 
escalation to administrative power.




Please update to Apache Sling Engine >= 2.14.0 and enable the "Check 
Content-Type overrides" configuration option.

Credit:

Lars Krapf (reporter)

References:

https://sling.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-45064

Reply via email to