{"id":"CVE-2012-2138","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-2138","summary":"Apache Sling POST Servlets Denial of Service Vulnerability","details":"The `@CopyFrom` operation in the POST servlet in the `org.apache.sling.servlets.post` bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.","published":"2022-05-17T05:28:00Z","modified":"2024-12-06T05:43:03.319734Z","cvss":null,"epss":{"score":0.14122,"percentile":0.96283,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.sling:org.apache.sling.servlets.post","fixedVersion":"2.1.2"}],"fix":{"url":"https://github.com/apache/sling-org-apache-sling-servlets-post/commit/0205892908d6ea755645be5fc16e9df53e2e7261","label":"apache/sling-org-apache-sling-servlets-post@0205892"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2138"},{"type":"WEB","url":"https://github.com/apache/sling-org-apache-sling-servlets-post/commit/0205892908d6ea755645be5fc16e9df53e2e7261"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SLING-2517"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/www-announce/201207.mbox/%3CCAEWfVJ=PwoQmwJg0KmbrC17Gw51kgfKRsqgy=4RpMQsdGh0bVg@mail.gmail.com%3E"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=1352865"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:43:03.319734Z"}}