Apache

Org.Apache.Sling.Servlets.Post

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.65%
  • Published 17.10.2013 23:55:04
  • Last modified 11.04.2025 00:51:21

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions t...

  • EPSS 25.44%
  • Published 09.07.2012 22:55:01
  • Last modified 11.04.2025 00:51:21

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service ...