CVE-2013-2254

CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.34 % (72th)
0.34% Progress
Affected Products 2
Advisories 1

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-10-17 23:55:04
(11 years ago)
Updated Date
2017-08-29 01:33:15
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Org.apache.sling.servlets.post 2.2.0 cpe:2.3:a:apache:org.apache.sling.servlets.post:2.2.0
OR  
  Running on/with
  Org.apache.sling.servlets.post 2.3.0 cpe:2.3:a:apache:org.apache.sling.servlets.post:2.3.0
OR  
  Running on/with
  Apache Sling cpe:2.3:a:apache:sling
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...