[MAVEN:GHSA-R2XF-W5PJ-9PW8] Apache Syncope JEXL Code Injection

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."

Package Affected Version
pkg:maven/org.apache.syncope/syncope >= 1.1.0, < 1.1.7
pkg:maven/org.apache.syncope/syncope >= 1.0.0, < 1.0.9
ID
MAVEN:GHSA-R2XF-W5PJ-9PW8
Severity
moderate
URL
https://github.com/advisories/GHSA-r2xf-w5pj-9pw8
Published
2022-05-14T01:18:38
(2 years ago)
Modified
2023-08-16T22:09:18
(13 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.syncope/syncope org.apache.syncope syncope >= 1.1.0 < 1.1.7
Fixed pkg:maven/org.apache.syncope/syncope org.apache.syncope syncope = 1.1.7
Affected pkg:maven/org.apache.syncope/syncope org.apache.syncope syncope >= 1.0.0 < 1.0.9
Fixed pkg:maven/org.apache.syncope/syncope org.apache.syncope syncope = 1.0.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...