Org.apache.sling:org.apache.sling.auth.core
This hub aggregates every CVE we track for Org.apache.sling:org.apache.sling.auth.core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
2
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
HIGH1MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 2 most recently published vulnerabilities affecting Org.apache.sling:org.apache.sling.auth.core.
- CVE-2017-15700A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send ove...8.8
- CVE-2013-4390Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to a...5.8
Product normalization is registry-driven with AI assist and human review. How it works