← All CVEs

CVE-2012-2138

medium · 5

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.

5
CVSS
14.1%
EPSS (exploit prob.)
96th
EPSS percentile
2012-07-09
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
apacheorg.apache.sling.servlets.post<= 2.1.0
apacheslingall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-2138