First published: Wed Jun 22 2022(Updated: )
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Sling API | <=2.25.0 | |
Apache Sling Commons Log | <=5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.