[MAVEN:GHSA-VJQW-R3WW-WJ2W] Expression Language Injection in Apache Syncope

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code.

Package Affected Version
pkg:maven/org.apache.syncope/syncope-core < 2.1.6
Package Fixed Version
pkg:maven/org.apache.syncope/syncope-core = 2.1.6
ID
MAVEN:GHSA-VJQW-R3WW-WJ2W
Severity
critical
URL
https://github.com/advisories/GHSA-vjqw-r3ww-wj2w
Published
2021-06-16T17:18:58
(3 years ago)
Modified
2023-02-01T05:05:46
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.syncope/syncope-core org.apache.syncope syncope-core < 2.1.6
Fixed pkg:maven/org.apache.syncope/syncope-core org.apache.syncope syncope-core = 2.1.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...