Apache Syncope
- >= 3.0.0-M0, <= 3.0.16
- >= 4.0.0-M0, <= 4.0.6
- >= 4.1.0-M0, <= 4.1.1
A remote code execution vulnerability has been identified in Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. This vulnerability arises from improper isolation in the connector subsystem, allowing an administrator with sufficient entitlements to execute arbitrary code by leveraging the capability of scripted connectors (REST and SQL) to run Groovy scripts.
Exploitation of this vulnerability allows for remote code execution on the server where Apache Syncope is running.
Users are advised to upgrade to Apache Syncope versions 4.0.7 or 4.1.2, which address this vulnerability by enhancing the security sandbox for Groovy scripts.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.