Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xgc9-9w4v-h33h

Опубликовано: 06 нояб. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

High severity vulnerability that affects org.apache.syncope:syncope-core

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11 and 2.0.x before 2.0.8 can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.

Пакеты

Наименование

org.apache.syncope:syncope-core

maven
Затронутые версииВерсия исправления

< 1.2.11

1.2.11

Наименование

org.apache.syncope:syncope-core

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.8

2.0.8

EPSS

Процентиль: 97%
0.17681
Средний

7.2 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.2
nvd
больше 8 лет назад

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.

CVSS3: 7.2
fstec
почти 8 лет назад

Уязвимость реализации технологии XSLT (eXtensible Stylesheet Language Transformations) системы для управления цифровыми идентификаторами Apache Syncope, позволяющая нарушителю осуществить чтение файла, запись файла или выполнить произвольный код

EPSS

Процентиль: 97%
0.17681
Средний

7.2 High

CVSS3

Дефекты

CWE-20