QID 981161

QID 981161: Java (maven) Security Update for org.apache.syncope:syncope-core (GHSA-9h9c-f287-c6vp)

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to refer to GHSA-9h9c-f287-c6vp for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981161

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9h9c-f287-c6vp org.apache.syncope:syncope-core URL Logo github.com/advisories/GHSA-9h9c-f287-c6vp