VYPR
High severity8.8NVD Advisory· Published Dec 18, 2017· Updated May 13, 2026

CVE-2017-15700

CVE-2017-15700

Description

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.sling:org.apache.sling.auth.coreMaven
>= 1.4.0, < 1.4.21.4.2

Affected products

1
  • Apache Software Foundation/Apache Slingv5
    Range: Authentication Service 1.4.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.