CVE-2022-45064 HIGH

CVE-2022-45064: Apache Sling Engine: Include-based XSS

Vendor Apache Software Foundation
Product Apache Sling Engine
Weakness CWE-79 · XSS
Published April 13, 2023
Last update October 17, 2024

CVSS base score

8.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

Description

The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific content-type and control the include path (i.e. writing content). The impact of a successful attack is privilege escalation to administrative power. Please update to Apache Sling Engine >= 2.14.0 and enable the "Check Content-Type overrides" configuration option.

Key dates

Disclosure timeline

April 13, 2023 CVE published
October 17, 2024 Record updated