CVE-2022-32549

MEDIUM

Apache Sling Commons Log <= 5.4.0 & Apache Sling API <= 2.25.0 - Co...

Title source: llm
STIX 2.1

Description

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

Scores

CVSS v3 5.3
EPSS 0.0286
EPSS Percentile 86.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-116 CWE-117
Status published
Products (4)
apache/sling_api < 2.25.0
apache/sling_commons_log < 5.4.0
org.apache.sling/org.apache.sling.api 0Maven
org.apache.sling/org.apache.sling.commons.log 0Maven
Published Jun 22, 2022
Tracked Since Feb 18, 2026