CVEs (1)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apache 1Sling Authentication Service May 13, 2026 Dec 18, 2017 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials. |