CVE-2012-2138
Last modified
CVE-2012-2138 is a vulnerability of currently unknown severity. The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.. EPSS estimates a 14.12% chance of exploitation in the next 30 days.
Description
The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Org.Apache.Sling.Servlets.Post | <= 2.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2138?
How severe is CVE-2012-2138?
How do I fix CVE-2012-2138?
Are you affected by CVE-2012-2138?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
