Lucene search

K
githubGitHub Advisory DatabaseGHSA-R2XF-W5PJ-9PW8
HistoryMay 14, 2022 - 1:18 a.m.

Apache Syncope JEXL Code Injection

2022-05-1401:18:38
CWE-94
GitHub Advisory Database
github.com
6

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

62.2%

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, “derived schema definition,” “user / role templates,” and “account links of resource mappings.”

Affected configurations

Vulners
Node
org.apache.syncope\Matchsyncope
OR
org.apache.syncope\Matchsyncope

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

62.2%