Closed dev-mend-for-github-com[bot] closed 1 year ago
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
Vulnerable Library - org.apache.sling.api-2.0.2-incubator.jar
The Sling API defines an extension to the Servlet API 2.4 to provide access to content and unified access to request parameters hiding the differences between the different methods of transferring parameters from client to server. Note that the Sling API bundle does not include the Servlet API but instead requires the API to be provided by the Servlet container in which the Sling framework is running or by another bundle.
Library home page: http://incubator.apache.org/sling/org.apache.sling.api
Path to dependency file: /app/pom.xml
Path to vulnerable library: /app/target/verademo/WEB-INF/lib/org.apache.sling.api-2.0.2-incubator.jar,/home/wss-scanner/.m2/repository/org/apache/sling/org.apache.sling.api/2.0.2-incubator/org.apache.sling.api-2.0.2-incubator.jar
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2015-2944
### Vulnerable Library - org.apache.sling.api-2.0.2-incubator.jarThe Sling API defines an extension to the Servlet API 2.4 to provide access to content and unified access to request parameters hiding the differences between the different methods of transferring parameters from client to server. Note that the Sling API bundle does not include the Servlet API but instead requires the API to be provided by the Servlet container in which the Sling framework is running or by another bundle.
Library home page: http://incubator.apache.org/sling/org.apache.sling.api
Path to dependency file: /app/pom.xml
Path to vulnerable library: /app/target/verademo/WEB-INF/lib/org.apache.sling.api-2.0.2-incubator.jar,/home/wss-scanner/.m2/repository/org/apache/sling/org.apache.sling.api/2.0.2-incubator/org.apache.sling.api-2.0.2-incubator.jar
Dependency Hierarchy: - :x: **org.apache.sling.api-2.0.2-incubator.jar** (Vulnerable Library)
Found in base branch: main
### Reachability AnalysisThe vulnerable code is not reachable.
### Vulnerability DetailsMultiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.
Publish Date: 2015-06-02
URL: CVE-2015-2944
### CVSS 2 Score Details (4.3)Base Score Metrics not available
### Suggested FixType: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2015-2944
Release Date: 2015-06-02
Fix Resolution: 2.2.2
:rescue_worker_helmet: Automatic Remediation will be attempted for this issue.:rescue_worker_helmet:Automatic Remediation will be attempted for this issue.