CVE-2023-25141
Last modified
CVE-2023-25141 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a remote location via JDNI and RMI. Users of Apache Sling JCR Base are recommended to upgrade to Apache Sling JCR Base 3.1.12 or later, or to run on a more recent JDK. . EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a remote location via JDNI and RMI. Users of Apache Sling JCR Base are recommended to upgrade to Apache Sling JCR Base 3.1.12 or later, or to run on a more recent JDK.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Sling Jcr Base | >= 2.0.6, < 3.1.12 |
References
- https://sling.apache.org/news.htmlVendor Advisory
- https://sling.apache.org/news.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25141?
How severe is CVE-2023-25141?
How do I fix CVE-2023-25141?
Are you affected by CVE-2023-25141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
