CVE-2017-15700

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
18/12/2017
Last modified:
20/04/2025

Description

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:sling_authentication_service:1.4.0:*:*:*:*:*:*:*