Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjqw-r3ww-wj2w

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Expression Language Injection in Apache Syncope

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code.

Пакеты

Наименование

org.apache.syncope:syncope-core

maven
Затронутые версииВерсия исправления

< 2.1.6

2.1.6

EPSS

Процентиль: 82%
0.01649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-917

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code.

EPSS

Процентиль: 82%
0.01649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-917