High severity8.8NVD Advisory· Published Dec 18, 2017· Updated May 13, 2026
CVE-2017-15700
CVE-2017-15700
Description
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.sling:org.apache.sling.auth.coreMaven | >= 1.4.0, < 1.4.2 | 1.4.2 |
Affected products
1- Apache Software Foundation/Apache Slingv5Range: Authentication Service 1.4.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-vcvp-89fq-hwj8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-15700ghsaADVISORY
- lists.apache.org/thread.html/182bed1dd6933824a81cc5f07639eeb813fbd8f2cc49d51b452ab621@%3Cdev.sling.apache.org%3EghsaWEB
- lists.apache.org/thread.html/182bed1dd6933824a81cc5f07639eeb813fbd8f2cc49d51b452ab621%40%3Cdev.sling.apache.org%3Envd
News mentions
0No linked articles in our index yet.