PT-2026-61603 · Apache · Apache Syncope
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Syncope versions 3.0.0-M0 through 3.0.16
Apache Syncope versions 4.0.0-M0 through 4.0.6
Apache Syncope versions 4.1.0-M0 through 4.1.1
Description
An improper isolation issue allows an administrator with sufficient entitlements to import arbitrary BPMN process definitions via the REST API and initiate the process. If the imported BPMN process contains a Groovy
scriptTask, the script is executed directly on the server without a sandbox, potentially leading to arbitrary code execution.Recommendations
Upgrade versions 3.0.0-M0 through 3.0.16 to version 4.0.7.
Upgrade versions 4.0.0-M0 through 4.0.6 to version 4.0.7.
Upgrade versions 4.1.0-M0 through 4.1.1 to version 4.1.2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Syncope