Описание
Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input.
The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling Commons Johnzon OSGi bundle provided by the Apache Sling project, but may of course use other JSON libraries.
Ссылки
- Product
- Vendor Advisory
- Mailing List
- Product
- Vendor Advisory
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.20 (включая)
cpe:2.3:a:apache:sling_commons_json:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00173
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 9.8
github
больше 2 лет назад
Apache Sling Commons JSON bundle vulnerable to Improper Input Validation
EPSS
Процентиль: 39%
0.00173
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-20