CVE-2012-3353
Summary
| CVE | CVE-2012-3353 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-09 02:29:00 UTC |
| Updated | 2023-11-07 02:11:00 UTC |
| Description | The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Sling Jcr Contentloader | 2.1.4 | All | All | All |
| Application | Apache | Sling Jcr Contentloader | 2.1.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | lists.apache.org | ||
| [SLING-2512] content loader shouldn't allow the use of file elements when location isn't available - ASF JIRA | CONFIRM | issues.apache.org | Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | Issue Tracking, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.