Apache Syncope
- >= 3.0.0-M0, <= 3.0.16
- >= 4.0.0-M0, <= 4.0.6
- >= 4.1.0-M0, <= 4.1.1
A vulnerability allowing remote code execution has been identified in Apache Syncope versions 3.0.0-M0 prior to 3.0.16, 4.0.0-M0 prior to 4.0.6, and 4.1.0-M0 prior to 4.1.1. This issue arises from improper isolation in the Groovy security sandbox, which can be bypassed by an administrator with the right entitlements. Such an administrator can create a malicious Groovy class containing untrusted code that exploits this weakness.
Exploitation of this vulnerability allows for remote code execution on the server where Apache Syncope is running.
Users are advised to upgrade to Apache Syncope versions 4.0.7 or 4.1.2, both of which address this vulnerability by reinforcing the Groovy security sandbox.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.