GHSA-gvg3-83q4-rfhq

Suggest an improvement
Source
https://github.com/advisories/GHSA-gvg3-83q4-rfhq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-gvg3-83q4-rfhq/GHSA-gvg3-83q4-rfhq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gvg3-83q4-rfhq
Aliases
  • CVE-2023-25141
Published
2023-02-14T15:30:28Z
Modified
2023-11-08T04:11:50.089358Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Command injection in Apache Sling
Details

Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a remote location via JDNI and RMI. Users of Apache Sling JCR Base are recommended to upgrade to Apache Sling JCR Base 3.1.12 or later, or to run on a more recent JDK.

Database specific
{
    "nvd_published_at": "2023-02-14T13:15:00Z",
    "cwe_ids": [
        "CWE-74"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-02-14T21:24:47Z",
    "severity": "HIGH"
}
References

Affected packages

Maven / org.apache.sling:org.apache.sling.jcr.base

Package

Name
org.apache.sling:org.apache.sling.jcr.base
View open source insights on deps.dev
Purl
pkg:maven/org.apache.sling/org.apache.sling.jcr.base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.12

Affected versions

2.*
2.0.2-incubator
2.0.4-incubator
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
2.3.2
2.4.0
2.4.2
3.*
3.0.0
3.0.2
3.0.4
3.0.6
3.1.0
3.1.4
3.1.6
3.1.8
3.1.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-gvg3-83q4-rfhq/GHSA-gvg3-83q4-rfhq.json"