PT-2026-61604 · Apache · Apache Syncope
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Syncope versions 3.0.0-M0 through 3.0.16
Apache Syncope versions 4.0.0-M0 through 4.0.6
Apache Syncope versions 4.1.0-M0 through 4.1.1
Description
Improper isolation or compartmentalization in the connector subsystem allows an administrator with adequate entitlements to achieve remote code execution. This is possible by leveraging the capability of scripted connectors, specifically REST and SQL, to execute Groovy scripts.
Recommendations
Upgrade versions 3.0.0-M0 through 3.0.16 to version 4.0.7.
Upgrade versions 4.0.0-M0 through 4.0.6 to version 4.0.7.
Upgrade versions 4.1.0-M0 through 4.1.1 to version 4.1.2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Syncope