{"id":"CVE-2012-2138","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-2138","summary":"The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant…","details":"The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.","published":"2012-07-09T22:55:01.027","modified":"2026-06-16T23:41:04.057","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/www-announce/201207.mbox/%3CCAEWfVJ=PwoQmwJg0KmbrC17Gw51kgfKRsqgy=4RpMQsdGh0bVg%40mail.gmail.com%3E"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=1352865"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SLING-2517"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/www-announce/201207.mbox/%3CCAEWfVJ=PwoQmwJg0KmbrC17Gw51kgfKRsqgy=4RpMQsdGh0bVg%40mail.gmail.com%3E"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=1352865"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SLING-2517"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:41:04.057"}}