Описание
Apache Syncope JEXL Code Injection
Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."
Пакеты
Наименование
org.apache.syncope:syncope
maven
Затронутые версииВерсия исправления
>= 1.0.0, < 1.0.9
1.0.9
Наименование
org.apache.syncope:syncope
maven
Затронутые версииВерсия исправления
>= 1.1.0, < 1.1.7
1.1.7
Связанные уязвимости
nvd
почти 12 лет назад
Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."