Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5677
HistoryJan 10, 2018 - 2:36 a.m.

Information Disclosure

2018-01-1002:36:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

31.1%

Apache Sling JCR ContentLoader is vulnerable to information disclosure. The application doesn’t properly check if a directory exists before importing files, allowing a malicious user access to arbitrary files.

CPENameOperatorVersion
apache sling jcr contentloaderle2.1.4

0.001 Low

EPSS

Percentile

31.1%

Related for VERACODE:5677