PT-2012-3830 · Apache · Apache Sling

Bertrand Delacretaz

·

Published

2012-07-09

·

Updated

2022-05-17

·

CVE-2012-2138

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Sling versions prior to 2.1.2
Description The issue allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request. This is due to the @CopyFrom operation in the POST servlet not preventing attempts to copy an ancestor node to a descendant node.
Recommendations For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the POST servlet to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2138
GHSA-342C-F869-5M44

Affected Products

Apache Sling