CVE-2012-2138

Org.apache.sling.servlets.post < 2.1.0 - Access Control

Title source: rule

Description

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by IOactive · textdosmultiple
https://www.exploit-db.com/exploits/37487

Scores

EPSS 0.4342
EPSS Percentile 97.5%

Details

CWE
CWE-264
Status published
Products (2)
apache/org.apache.sling.servlets.post < 2.1.0
org.apache.sling/org.apache.sling.servlets.post 0 - 2.1.2Maven
Published Jul 09, 2012
Tracked Since Feb 18, 2026