QID 982240

QID 982240: Java (maven) Security Update for org.apache.syncope:syncope (GHSA-p2rp-cmjq-r7wm)

In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Customers are advised to refer to GHSA-p2rp-cmjq-r7wm for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982240

    Software Advisories
    Advisory ID Software Component Link
    GHSA-p2rp-cmjq-r7wm org.apache.syncope:syncope URL Logo github.com/advisories/GHSA-p2rp-cmjq-r7wm