Executive brief
Apache Sling Security Bundle contains a weakness in the ReferrerFilter component that allows it to accept weaker HTTP Referer validation evidence than the Origin header standard requires. This bypass could allow attackers to perform cross-site request forgery (CSRF) attacks against applications relying on this filter, potentially leading to unauthorized actions or account compromise.
Technical details
The ReferrerFilter in Apache Sling Security Bundle before version 1.3.2 improperly validates HTTP Referer headers with insufficient strictness compared to Origin header validation, enabling CSRF attacks. The vulnerability requires the victim to visit an attacker-controlled web page while logged into a vulnerable Sling application, but does not require code execution or elevated privileges. A fix is available in version 1.3.2.
Affected products
- Apache Sling Security Bundle before 1.3.2
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fix available in version 1.3.2