5
CVSSv2

CVE-2022-32549

Published: 22/06/2022 Updated: 29/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an malicious user to cover tracks by injecting fake logs and potentially corrupt log files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache sling commons log

apache sling api

Vendor Advisories

Apache Sling Commons Log &amp;lt;= 540 and Apache Sling API &amp;lt;= 2250 are vulnerable to log injection The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files ...