QID 982240
QID 982240: Java (maven) Security Update for org.apache.syncope:syncope (GHSA-p2rp-cmjq-r7wm)
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p2rp-cmjq-r7wm for updates pertaining to this vulnerability.
Vendor References
- GHSA-p2rp-cmjq-r7wm -
github.com/advisories/GHSA-p2rp-cmjq-r7wm
CVEs related to QID 982240
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p2rp-cmjq-r7wm | org.apache.syncope:syncope |
|