CVE-2017-9802
Summary
| CVE | CVE-2017-9802 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-14 13:29:00 UTC |
| Updated | 2023-11-07 02:50:00 UTC |
| Description | The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Sling Servlets Post | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Sling Servlets Post CVE-2017-9802 Cross Site Scripting Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Pony Mail! | lists.apache.org | ||
| Apache Sling Servlets Post 2.3.20 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| [SLING-7041] Use JSON parsing in Sling.evalString - ASF JIRA | CONFIRM | issues.apache.org | Issue Tracking, Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.