Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5589
HistoryDec 19, 2017 - 5:41 a.m.

Unvalidated Redirection Attack

2017-12-1905:41:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.001 Low

EPSS

Percentile

28.8%

org.apache.sling.auth.core is vulnerable to unvalidated redirection attacks. The vulnerability exists due to the lack validation of user input from the Sling login form which allows an attacker to send victims credentials.

CPENameOperatorVersion
apache sling auth corele1.4.0

0.001 Low

EPSS

Percentile

28.8%

Related for VERACODE:5589