← Back

Sling Authentication Service

sling_authentication_service

Vendor: Apache • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Sling Authentication Service
May 13, 2026
Dec 18, 2017
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.