CVE-2012-3353
published 2018-01-09CVE-2012-3353: The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
3.14%
86.4th percentile
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | sling_jcr_contentloader | — | — |
| apache_software_foundation | apache_sling | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Sling JCR ContentLoader XmlReader Arbitrary File Load
ghsa·2022-05-14
CVE-2012-3353 [HIGH] CWE-200 Apache Sling JCR ContentLoader XmlReader Arbitrary File Load
Apache Sling JCR ContentLoader XmlReader Arbitrary File Load
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader
OSV
Apache Sling JCR ContentLoader XmlReader Arbitrary File Load
osv·2022-05-14
CVE-2012-3353 [HIGH] Apache Sling JCR ContentLoader XmlReader Arbitrary File Load
Apache Sling JCR ContentLoader XmlReader Arbitrary File Load
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.apache.org/jira/browse/SLING-2512https://lists.apache.org/thread.html/50994d80dd5cf93f1365dacfcaecf5c12f1efe522c4ff6040b3c521a%40%3Cdev.sling.apache.org%3Ehttps://issues.apache.org/jira/browse/SLING-2512https://lists.apache.org/thread.html/50994d80dd5cf93f1365dacfcaecf5c12f1efe522c4ff6040b3c521a%40%3Cdev.sling.apache.org%3E
2018-01-09
Published