Description
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.
Remediation
References
https://lists.apache.org/thread.html/182bed1dd6933824a81cc5f07639eeb813fbd8f2cc49d51b452ab621%40%3Cdev.sling.apache.org%3E
Related Vulnerabilities
CVE-2018-1337 Vulnerability in maven package org.apache.directory.api:api-ldap-client-api
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:api-all
CVE-2017-1000398 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-22135 Vulnerability in maven package org.elasticsearch:elasticsearch