CVE-2022-32549
MEDIUMApache Sling Commons Log <= 5.4.0 & Apache Sling API <= 2.25.0 - Co...
Title source: llmDescription
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
Scores
CVSS v3
5.3
EPSS
0.0286
EPSS Percentile
86.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-116
CWE-117
Status
published
Products (4)
apache/sling_api
< 2.25.0
apache/sling_commons_log
< 5.4.0
org.apache.sling/org.apache.sling.api
0Maven
org.apache.sling/org.apache.sling.commons.log
0Maven
Published
Jun 22, 2022
Tracked Since
Feb 18, 2026