SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-9802

The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings.

MEDIUM 6.1EPSS 3.66%

Does this matter?

Lower severity and a low EPSS score (3.66%). Track it; it rarely justifies an emergency change on its own.

Description

The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
3.66% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/sling servlets post
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.