PT-2018-4050 · Apache · Apache Sling Jcr Contentloader

Bertrand Delacretaz

·

Published

2018-01-08

·

Updated

2022-05-14

·

CVE-2012-3353

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Sling JCR ContentLoader versions 2.1.4
Description The issue allows the import of arbitrary files in the content repository, including local files, potentially causing information leaks.
Recommendations For Apache Sling JCR ContentLoader version 2.1.4, upgrade to version 2.1.6 of the JCR ContentLoader.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3353
GHSA-WJP3-4XCQ-598P

Affected Products

Apache Sling Jcr Contentloader