Open Redirect Vulnerability in Apache Sling Auth Core
CVE-2013-4390

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 October 2013

What is CVE-2013-4390?

An open redirect vulnerability exists in the AbstractAuthenticationFormServlet within the Auth Core of Apache Sling versions prior to 1.1.4. This flaw enables remote attackers to manipulate the resource parameter to redirect users to arbitrary external sites. As a result, this can facilitate phishing attacks by deceiving users into providing sensitive information under the guise of a legitimate authentication process.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.