github / advisory-database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Creative Commons Attribution 4.0 International
1.67k stars 305 forks source link

[GHSA-qmx3-m648-hr74] Log Injection in Apache Sling Commons Log and Apache Sling API #4505

Closed SunBK201 closed 1 day ago

SunBK201 commented 1 month ago

Updates

Comments https://mvnrepository.com/artifact/org.apache.sling/org.apache.sling.api

shelbyc commented 1 month ago

Hi @SunBK201, https://mvnrepository.com/artifact/org.apache.sling/org.apache.sling.api doesn't say anything about version 2.25.4 containing a patch for GHSA-qmx3-m648-hr74. Do you have other links supporting adding 2.25.4 as a patched version?