Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxwh-vmhg-39r2

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Sling

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

Пакеты

Наименование

org.apache.sling:org.apache.sling.api

maven
Затронутые версииВерсия исправления

<= 2.3.0

2.4.0

EPSS

Процентиль: 76%
0.00992
Низкий

Дефекты

CWE-119

Связанные уязвимости

nvd
больше 12 лет назад

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

EPSS

Процентиль: 76%
0.00992
Низкий

Дефекты

CWE-119