This is an automated email from the ASF dual-hosted git repository.

angela pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/sling-site.git


The following commit(s) were added to refs/heads/master by this push:
     new d81ff7dea update news
d81ff7dea is described below

commit d81ff7dea573ecaed70ba0ddd4333638d9b58b74
Author: angela <[email protected]>
AuthorDate: Wed Apr 12 18:37:22 2023 +0200

    update news
---
 src/main/jbake/content/news.md | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/src/main/jbake/content/news.md b/src/main/jbake/content/news.md
index e1ed49a7c..50c5440a6 100644
--- a/src/main/jbake/content/news.md
+++ b/src/main/jbake/content/news.md
@@ -5,8 +5,10 @@ tags=news
 tableOfContents=false
 ~~~~~~
 
+* Vulnerability report and fix: CVE-2022-45064: Apache Sling Engine: 
Include-based XSS (April 12th, 2023), see 
[https://www.cve.org/CVERecord?id=CVE-2022-45064](https://www.cve.org/CVERecord?id=CVE-2022-45064)
+* Vulnerability report and fix: CVE-2023-25621: Apache Sling does not allow to 
handle i18n content in a secure way (Feb 23rd, 2023), see 
[https://www.cve.org/CVERecord?id=CVE-2023-25621](https://www.cve.org/CVERecord?id=CVE-2023-25621)
 * Vulnerability report and fix: CVE-2023-25141: Apache Sling JCR Base JNDI 
injection (February 14th, 2023), see 
[https://www.cve.org/CVERecord?id=CVE-2023-25141](https://www.cve.org/CVERecord?id=CVE-2023-25141)
-* Vulnerability report and fix: VE-2023-22849: Apache Sling App CMS: XSS in 
CMS Reference / UI Components (Feb 3rd, 2023), see 
[https://www.cve.org/CVERecord?id=CVE-2023-22849](https://www.cve.org/CVERecord?id=CVE-2023-22849)
+* Vulnerability report and fix: CVE-2023-22849: Apache Sling App CMS: XSS in 
CMS Reference / UI Components (Feb 3rd, 2023), see 
[https://www.cve.org/CVERecord?id=CVE-2023-22849](https://www.cve.org/CVERecord?id=CVE-2023-22849)
 * Vulnerability report and fix: CVE-2022-46769: Apache Sling CMS Reflected XSS 
Vulnerability (January 1st, 2022), see 
[https://www.cve.org/CVERecord?id=CVE-2022-46769](https://www.cve.org/CVERecord?id=CVE-2022-46769)
 * Vulnerability report and fix: CVE-2022-43670: Apache Sling CMS Reflected XSS 
Vulnerability (November 1st, 2022), see 
[http://s.apache.org/CVE-2022-43670](http://s.apache.org/CVE-2022-43670)
 * Released [Apache Sling 12](/news/sling-12-released.html) (March 18th, 2022).

Reply via email to