{"id":"GHSA-cxwh-vmhg-39r2","summary":"Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Sling","details":"The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.","aliases":["CVE-2013-2254"],"modified":"2024-12-06T05:35:23.629453Z","published":"2022-05-17T01:36:04Z","database_specific":{"github_reviewed_at":"2022-07-08T19:14:16Z","nvd_published_at":"2013-10-17T23:55:00Z","cwe_ids":["CWE-119"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2254"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/87765"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SLING-2913"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/sling-dev/201310.mbox/%3CCAKkCf4pue6PnESsP1KTdEDJm1gpkANFaK%2BvUd9mzEVT7tXL%2B3A%40mail.gmail.com%3E"}],"affected":[{"package":{"name":"org.apache.sling:org.apache.sling.api","ecosystem":"Maven","purl":"pkg:maven/org.apache.sling/org.apache.sling.api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.0"}]}],"versions":["2.0.2-incubator","2.0.4-incubator","2.0.6","2.0.8","2.1.0","2.2.0","2.2.2","2.2.4","2.3.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.3.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cxwh-vmhg-39r2/GHSA-cxwh-vmhg-39r2.json"}}],"schema_version":"1.9.0"}