CVE-2022-32549

MEDIUM5.3EPSS 2.9%

Log Injection in Apache Sling Commons Log and Apache Sling API

發布日:2022/6/23修改日:2023/11/8

描述

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

參考連結(2)