GHSA-8c82-9rgp-4qvr
Dashboard / Vulnerabilities / GHSA-8c82-9rgp-4qvr
Summary: Improper Neutralization of Input During Web Page Generation Apache Sling Servlets Post
Details: The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-9802, https://issues.apache.org/jira/browse/SLING-7041, https://lists.apache.org/thread.html/2f4b8333e44c6e7e0b00933bd4204ce64829952f60dbb6814f2cdf91@%3Cdev.sling.apache.org%3E, http://packetstormsecurity.com/files/143758/Apache-Sling-Servlets-Post-2.3.20-Cross-Site-Scripting.html, http://www.securityfocus.com/archive/1/541024/100/0/threaded, http://www.securityfocus.com/bid/100284
Affected packages
Package
Name: org.apache.sling:org.apache.sling.servlets.post
Purl: pkg:maven/org.apache.sling/org.apache.sling.servlets.post
Affected ranges
Type: ECOSYSTEM
Events:
