CVE-2013-4390
Summary
| CVE | CVE-2013-4390 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-24 03:48:48 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the resource parameter, related to "a custom login form and XSS." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Sling | All | All | All | All |
| Application | Apache | Sling Auth Core Component | 1.0.2 | All | All | All |
| Application | Apache | Sling Auth Core Component | 1.0.4 | All | All | All |
| Application | Apache | Sling Auth Core Component | 1.0.6 | All | All | All |
| Application | Apache | Sling Auth Core Component | 1.1.0 | All | All | All |
| Application | Apache | Sling Auth Core Component | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE-2013-4390: Apache Sling open redirect on login | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | Vendor Advisory |
| Security Advisory SA55249 - Apache Sling Auth Core Component "resource" Open Redirection Weakness - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SLING-3141] AbstractAuthenticationFormServlet should make sure resource is a valid redirect - ASF JIRA | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.