Apache Syncope
- >= 3.0.0-M0, <= 3.0.16
- >= 4.0.0-M0, <= 4.0.6
- >= 4.1.0-M0, <= 4.1.1
A vulnerability allowing remote code execution has been identified in Apache Syncope versions 3.0.0-M0 prior to 3.0.16, 4.0.0-M0 prior to 4.0.6, and 4.1.0-M0 prior to 4.1.1. This issue arises from improper isolation in the handling of BPMN process definitions. An administrator with the necessary entitlements can import arbitrary BPMN processes via the REST API. Once imported, these processes can be started, and if they include a Groovy scriptTask, the script is executed on the server without any sandboxing, posing a significant security risk.
Exploitation of this vulnerability allows for remote code execution on the server where Apache Syncope is running.
Users are advised to upgrade to Apache Syncope versions 4.0.7 or 4.1.2, which address this vulnerability by adding a security sandbox around Flowable's Groovy scriptTasks.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.