rootpwn

high · CVSS v3 7.3 · EPSS 0.00128

CVE-2026-94243

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affec…

Description

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.3
CVSS v4
EPSS
0.00128

← All CVEs