Impact
The Apache Sling Security Bundle ReferrerFilter accepts referrer evidence that is weaker than the originating server, allowing an attacker to forge or modify the Referer header and undermine the frameworkâs security controls that rely on strict origin validation. This flaw can be exploited to bypass access restrictions that depend on the Referer header, potentially granting unauthorized access to protected resources.
Affected Systems
All installations of the Apache Sling Security Bundle that are running a version earlier than 1.3.2 are affected, regardless of deployment environment. The vulnerability is present in any release before the fix included in bundle version 1.3.2.
Risk and Exploitability
The EPSS score is under 1%, indicating a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to send HTTP requests with a forged Referer header, typically over an open network connection. While the CVSS metric is not supplied, the CWE-346 weakness and the reliance on forged headers suggest that a skilled attacker could gain unauthorized access if Referer validation is trusted for authorization.
OpenCVE Enrichment