SCA: security update for org.apache.sling:org.apache.sling.servlets.resolver (GHSA-h2rq-qhr7-53gm)

high Tenable Cloud Security Plugin ID 415412

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets
Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether
a system is vulnerable to this attack depends on the exact configuration of the system. If the system is
vulnerable, a user with write access to the repository might be able to trick the Sling Servlet Resolver
to load a previously uploaded script. Users are recommended to upgrade to version 2.11.0, which fixes this
issue. It is recommended to upgrade, regardless of whether your system configuration currently allows this
attack or not. (CVE-2024-23673)

See Also

https://github.com/advisories/GHSA-h2rq-qhr7-53gm

Plugin Details

Severity: High

ID: 415412

Version: Revision 1.13

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.86

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-23673

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/6/2024

Vulnerability Publication Date: 2/6/2024

Reference Information

CVE: CVE-2024-23673

cwe: CWE-22