org.apache.syncope:syncope-core
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.syncope:syncope-corepage 1 of 1
- CVE-2018-1321HIGHCVSS 7.2✓ Fixed in 2.0.82018-03-20
vulnerable: 2.0.0 ... 2.0.7 (8 versions)
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious …
- CVE-2018-1322MEDIUMCVSS 4.9✓ Fixed in 2.0.82018-03-20
vulnerable: 2.0.0 ... 2.0.7 (8 versions)
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby…
- CVE-2018-17184MEDIUMCVSS 5.4✓ Fixed in 2.1.22018-11-06
vulnerable: 2.1.0, 2.1.1
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administra…
- CVE-2018-17186HIGHCVSS 7.2✓ Fixed in 2.1.22018-11-06
vulnerable: 2.1.0, 2.1.1
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
- CVE-2020-1959CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.1.62020-05-04
vulnerable: 1.0.0-RC1-incubating ... 2.1.5 (63 versions)
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java …
- CVE-2020-1961CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.1.62020-05-04
vulnerable: 2.1.0 ... 2.1.5 (6 versions)
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (…
Check whether org.apache.syncope:syncope-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.syncope:syncope-core CVEs against the assets you own.
Start Free Scan →