QID 981161
QID 981161: Java (maven) Security Update for org.apache.syncope:syncope-core (GHSA-9h9c-f287-c6vp)
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9h9c-f287-c6vp for updates pertaining to this vulnerability.
Vendor References
- GHSA-9h9c-f287-c6vp -
github.com/advisories/GHSA-9h9c-f287-c6vp
CVEs related to QID 981161
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9h9c-f287-c6vp | org.apache.syncope:syncope-core |
|