{"id":"CVE-2013-2254","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-2254","summary":"Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Sling","details":"The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.","published":"2022-05-17T01:36:04Z","modified":"2024-12-06T05:35:23.629453Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.sling:org.apache.sling.api","fixedVersion":"2.4.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2254"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/87765"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SLING-2913"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/sling-dev/201310.mbox/%3CCAKkCf4pue6PnESsP1KTdEDJm1gpkANFaK%2BvUd9mzEVT7tXL%2B3A%40mail.gmail.com%3E"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:35:23.629453Z"}}