CVE-2017-15700: Apache Sling Authentication Service
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.
Affected products
- Apache Sling Authentication Service: version 1.4.0 only
Published 2017-12-18. Last modified 2026-06-17.