First published: Wed Jun 22 2022(Updated: )
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Sling API | <=2.25.0 | |
Apache Sling Commons Log | <=5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32549 is classified as a high severity vulnerability due to its potential to allow attackers to forge logs and cover their tracks.
To fix CVE-2022-32549, upgrade Apache Sling API to version 2.26.0 or later and Apache Sling Commons Log to version 5.4.1 or later.
CVE-2022-32549 can facilitate log injection attacks, potentially allowing attackers to insert fake logs into log files.
CVE-2022-32549 affects Apache Sling Commons Log versions up to 5.4.0 and Apache Sling API versions up to 2.25.0.
Yes, CVE-2022-32549 compromises log integrity, as attackers can inject falsified logs that may corrupt log files.