PT-2026-43079 · Apache · Apache Syncope
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Syncope versions 3.0 through 3.0.16
Apache Syncope versions 4.0 through 4.0.5
Apache Syncope version 4.1.0
Description
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL (Java Expression Language) expression. This allows any administrator with sufficient entitlements for User read to access security-sensitive information related to users.
Recommendations
For versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0, upgrade to version 4.0.6 or 4.1.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Syncope