Apache Sling Engine: Include-based XSS
CVE-2022-45064

9CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
13 April 2023

What is CVE-2022-45064?

A notable vulnerability exists in the Apache Sling Engine where the SlingRequestDispatcher fails to correctly implement the RequestDispatcher API. This flaw creates opportunities for a generic type of include-based cross-site scripting attacks at the Apache Sling level. Attackers can exploit this vulnerability by including a resource with specific content-types and controlling the include path. This unauthorized access can lead to serious consequences, such as privilege escalation to administrative roles. To mitigate this risk, it is crucial to update to Apache Sling Engine version 2.14.0 or later and to enable the 'Check Content-Type overrides' configuration option.

Affected Version(s)

Apache Sling Engine < 2.14.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lars Krapf
.