seeing is believing

Apache Sling 1.1.2 Open Redirect

Apache Sling 1.1.2 Open Redirect
Posted Oct 21, 2013
Authored by Raphael Wegmueller

Apache Sling versions 1.1.2 and below suffer from an open redirect vulnerability.

tags | advisory
advisories | CVE-2013-4390
MD5 | d6fae13768e316cc0ccc7b9fb9add1eb

Apache Sling 1.1.2 Open Redirect

Change Mirror Download
CVE-2013-4390: Apache Sling open redirect on login

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected: All versions Apache Sling org.apache.sling.auth.core up
to and including version 1.1.2

Description: With some combinations of a custom login form and XSS the
login form rendered by the Apache Sling Auth Core bundle is attackable with
an open redirect, sending users to any server after a login.

Mitigation: Users of those bundle versions should update to version 1.1.4
of the bundle (http://sling.apache.org/downloads.cgi)

Credit: This issue was reported by Raphael Wegmueller of Adobe Systems
Incorporated.

References: http://sling.apache.org/project-information/security.html

https://issues.apache.org/jira/browse/SLING-3141
Regards

Carsten Ziegeler
On Behalf of the Apache Sling Project Management Committee

--
Carsten Ziegeler
cziegeler@apache.org

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

February 2015

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    2 Files
  • 2
    Feb 2nd
    17 Files
  • 3
    Feb 3rd
    15 Files
  • 4
    Feb 4th
    16 Files
  • 5
    Feb 5th
    14 Files
  • 6
    Feb 6th
    4 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2015 Packet Storm. All rights reserved.

close