Vulnerabilities (CVE)

Filtered by vendor Apache
Filtered by product Sling Servlets Resolver
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23673 1 Apache 1 Sling Servlets Resolver 2025-02-13 N/A 8.5 HIGH
Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system. If the system is vulnerable, a user with write access to the repository might be able to trick the Sling Servlet Resolver to load a previously uploaded script.  Users are recommended to upgrade to version 2.11 ...

Show More