QID 980936
QID 980936: Java (maven) Security Update for org.apache.syncope:syncope-core (GHSA-qfjv-998w-q48f)
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qfjv-998w-q48f for updates pertaining to this vulnerability.
Vendor References
- GHSA-qfjv-998w-q48f -
github.com/advisories/GHSA-qfjv-998w-q48f
CVEs related to QID 980936
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qfjv-998w-q48f | org.apache.syncope:syncope-core |
|