CVE-2022-47937

CVE-2022-47937: Multiple parsing problems in the Apache Sling Commons JSON module

Vendor Apache Software Foundation
Product org.apache.sling.commons.json
Weakness CWE-20 · Input validation
Published May 15, 2023
Last update October 10, 2024

CVSS base score

What the vulnerability does

Description

Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are encouraged to consider the Apache Sling Commons Johnzon OSGi bundle provided by the Apache Sling project, but may of course use other JSON libraries.

Key dates

Disclosure timeline

May 15, 2023 CVE published
October 10, 2024 Record updated