Apache Syncope
- >= 3.0.0-M0, <= 3.0.16
- >= 4.0.0-M0, <= 4.0.6
- >= 4.1.0-M0, <= 4.1.1
A vulnerability in Apache Syncope related to improper privilege management has been identified. This issue arises when the all-Java user workflow adapter or the Flowable user workflow adapter is used, with a BPMN definition that does not require administrative approval for user self-registration or self-update requests. Under these conditions, a user can make a REST API call to assign themselves one or more defined roles. This unauthorized role assignment grants them corresponding entitlements, effectively allowing them to assume administrative privileges. The specific entitlements gained depend on the roles defined in the affected Syncope deployment. This vulnerability affects Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1.
Exploitation of this vulnerability allows users to escalate privileges by assigning themselves administrative roles, thereby gaining full administrative rights and entitlements within the application.
Users are advised to upgrade to Apache Syncope versions 4.0.7 or 4.1.2, both of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.