AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-25141

HIGH · CVSS 7.5 EPSS 1.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-02-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-25141
Severity
HIGH
CVSS
7.5
EPSS
1.16%
Apache

Original NVD Description

Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a remote location via JDNI and RMI. Users of Apache Sling JCR Base are recommended to upgrade to Apache Sling JCR Base 3.1.12 or later, or to run on a more recent JDK.