SCA: security update for org.apache.sling:org.apache.sling.i18n (GHSA-mrpv-5pmr-p92h)

medium Tenable Cloud Security Plugin ID 417117

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able
to create i18n dictionaries in the repository in a location the author has write access to. As these
translations are used across the whole product, it allows an author to change any text or dialog in the
product. For example an attacker might fool someone by changing the text on a delete button to "Info".
This issue affects the i18n module of Apache Sling up to version 2.5.18. Version 2.6.2 and higher limit by
default i18m dictionaries to certain paths in the repository (/libs and /apps). Users of the module are
advised to update to version 2.6.2 or higher, check the configuration for resource loading and then adjust
the access permissions for the configured path accordingly. (CVE-2023-25621)

See Also

https://github.com/advisories/GHSA-mrpv-5pmr-p92h

Plugin Details

Severity: Medium

ID: 417117

Version: Revision 1.13

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2023-25621

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/23/2023

Vulnerability Publication Date: 2/23/2023

Reference Information

CVE: CVE-2023-25621

cwe: CWE-269