{"id":"CVE-2022-32549","summary":"log injection in Sling logging","details":"Apache Sling Commons Log \u003c= 5.4.0 and Apache Sling API \u003c= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.","aliases":["GHSA-qmx3-m648-hr74"],"modified":"2026-08-12T03:51:30.387643458Z","published":"2022-06-22T14:25:10Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32549.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"Apache Sling API"},{"last_affected":"2.25.0"},{"introduced":"Apache Sling Commons Log"},{"last_affected":"5.4.0"}]}],"cna_assigner":"apache","cwe_ids":["CWE-117"]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread/7z6h3806mwcov5kx6l96pq839sn0po1v"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32549.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32549"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/sling-org-apache-sling-api","events":[{"introduced":"0"},{"last_affected":"ae20adbe8613e56ce2cd9db6a2c4195b20732841"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:sling_api:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.25.0"}]}}],"versions":["org.apache.sling.api-2.25.0","org.apache.sling.api-2.24.0","org.apache.sling.api-2.23.6","org.apache.sling.api-2.23.4","org.apache.sling.api-2.23.0","org.apache.sling.api-2.22.0","org.apache.sling.api-2.21.0","org.apache.sling.api-2.20.0","org.apache.sling.api-2.18.4","org.apache.sling.api-2.18.2","org.apache.sling.api-2.18.0","org.apache.sling.api-2.17.0","org.apache.sling.api-2.16.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32549.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/apache/sling-org-apache-sling-commons-log","events":[{"introduced":"0"},{"last_affected":"1608fa6aec3ad3abc8b3514875ae79b7507c2c63"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.4.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:sling_commons_log:*:*:*:*:*:*:*:*"}}],"versions":["org.apache.sling.commons.log-5.4.0","org.apache.sling.commons.log-5.3.0","org.apache.sling.commons.log-5.2.0","org.apache.sling.commons.log-5.1.14","org.apache.sling.commons.log-5.1.12","org.apache.sling.commons.log-5.1.10","org.apache.sling.commons.log-5.1.8","org.apache.sling.commons.log-5.1.6","org.apache.sling.commons.log-5.1.4","org.apache.sling.commons.log-5.1.2","org.apache.sling.commons.log-5.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32549.json"}}],"schema_version":"1.9.0"}