Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-825g-mm5v-ggq4

Опубликовано: 20 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Apache Syncope allows malicious administrators to inject Groovy code

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.

Пакеты

Наименование

org.apache.syncope.core:syncope-core-spring

maven
Затронутые версииВерсия исправления

< 3.0.14

3.0.14

Наименование

org.apache.syncope.core:syncope-core-spring

maven
Затронутые версииВерсия исправления

>= 4.0.0-M0, < 4.0.2

4.0.2

EPSS

Процентиль: 27%
0.00094
Низкий

7.2 High

CVSS3

Дефекты

CWE-653

Связанные уязвимости

CVSS3: 7.2
nvd
4 месяца назад

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.

CVSS3: 7.2
fstec
5 месяцев назад

Уязвимость системы для управления цифровыми идентификаторами Apache Syncope, связанная с отсутствием контроля разрешений приложений, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 27%
0.00094
Низкий

7.2 High

CVSS3

Дефекты

CWE-653