PT-2023-20199 · Apache · Apache Sling
Published
2023-02-23
·
Updated
2025-03-18
·
CVE-2023-25621
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Sling versions prior to 2.6.2
Description
A privilege escalation issue exists in the i18n module of Apache Sling, allowing any content author to create i18n dictionaries in the repository in a location they have write access to. These translations are used across the whole product, enabling an author to change any text or dialog in the product. For example, an attacker might fool someone by changing the text on a delete button to "Info".
Recommendations
Update to version 2.6.2 or higher, check the configuration for resource loading, and then adjust the access permissions for the configured path accordingly.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Sling