Tracker / CVE-2022-32549
CVE-2022-32549
Medium 5.3
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
Affected products and versions
| apache | sling_api · … → 2.25.0 |
|---|---|
| apache | sling_commons_log · … → 5.4.0 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.