CVE-2012-3353

The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:sling_jcr_contentloader:2.1.4:*:*:*:*:*:*:*

History

07 Nov 2023, 02:11

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/50994d80dd5cf93f1365dacfcaecf5c12f1efe522c4ff6040b3c521a@%3Cdev.sling.apache.org%3E', 'name': '[dev] 20180108 CVE-2012-3353: Apache Sling Content Loading Vulnerability', 'tags': ['Issue Tracking', 'Mailing List', 'Third Party Advisory'], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/50994d80dd5cf93f1365dacfcaecf5c12f1efe522c4ff6040b3c521a%40%3Cdev.sling.apache.org%3E -

Information

Published : 2018-01-09 02:29

Updated : 2024-02-28 16:04


NVD link : CVE-2012-3353

Mitre link : CVE-2012-3353

CVE.ORG link : CVE-2012-3353


JSON object : View

Products Affected

apache

  • sling_jcr_contentloader
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor