CVE-2022-32549

MEDIUM

Apache Sling Commons Log <= 5.4.0 & Apache Sling API <= 2.25.0 - Co...

Title source: llm
STIX 2.1

Description

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

References (1)

Core 1
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread/7z6h3806mwcov5kx6l96pq839sn0po1v

Scores

CVSS v3 5.3
EPSS 0.0204
EPSS Percentile 78.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-116 CWE-117
Status published
Products (4)
apache/sling_api < 2.25.0
apache/sling_commons_log < 5.4.0
org.apache.sling/org.apache.sling.api 0Maven
org.apache.sling/org.apache.sling.commons.log 0Maven
Published Jun 22, 2022
Tracked Since Feb 18, 2026