PT-2013-3625 · Apache · Apache Sling

Antonio Sanso

·

Published

2013-10-17

·

Updated

2022-05-17

·

CVE-2013-2254

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Sling org.apache.sling.servlets.post.bundle versions 2.2.0 through 2.3.0
Description The issue arises from the deepGetOrCreateNode function in AbstractCreateOperation.java, which fails to handle a NULL value returned when the session lacks permissions to the root node. This oversight allows remote attackers to trigger a denial of service, specifically an infinite loop, via unspecified vectors.
Recommendations For versions 2.2.0 and 2.3.0, consider restricting access to the deepGetOrCreateNode function in AbstractCreateOperation.java until a patch is available to properly handle NULL values and prevent infinite loops.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2254
GHSA-CXWH-VMHG-39R2

Affected Products

Apache Sling