Back to search
CVE-2022-32549
Published: Jun 22, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Sling | affected Apache Sling API - <= 2.25.0affected Apache Sling Commons Log - <= 5.4.0 |
Weaknesses (CWE)
References
https://lists.apache.org/thread/7z6h3806mwcov5kx6l96pq839sn0po1v
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now