PT-2023-14581 · Apache · Apache Sling Engine

Lars Krapf

·

Published

2023-04-13

·

Updated

2025-06-13

·

CVE-2022-45064

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Sling Engine versions prior to 2.14.0
Description The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API, resulting in include-based cross-site scripting issues on the Apache Sling level. An attacker who can include a resource with a specific content-type and control the include path can exploit this issue, leading to privilege escalation to administrative power.
Recommendations Update to Apache Sling Engine version 2.14.0 or newer and enable the "Check Content-Type overrides" configuration option.

Fix

LPE

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-45064
GHSA-MG46-F9H5-G27X

Affected Products

Apache Sling Engine