VYPR

Sling JCR Base

by Apache

Source repositories

CVEs (1)

  • CVE-2023-25141Feb 14, 2023
    risk 0.00cvss epss 0.02

    Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a…