org.apache.syncope:syncope-core
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.syncope:syncope-corepage 1 of 1
- CVE-2018-1321HIGHCVSS 7.2EG 7.2✓ Fixed in 2.0.82018-03-20
vulnerable: 2.0.0 ... 2.0.7 (8 versions)
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious …
- CVE-2018-1322MEDIUMCVSS 4.9EG 4.9✓ Fixed in 2.0.82018-03-20
vulnerable: 2.0.0 ... 2.0.7 (8 versions)
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby…
- CVE-2018-17184MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.1.22018-11-06
vulnerable: 2.1.0, 2.1.1
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administra…
- CVE-2018-17186HIGHCVSS 7.2EG 7.2✓ Fixed in 2.1.22018-11-06
vulnerable: 2.1.0, 2.1.1
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
- CVE-2020-1959CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.1.62020-05-04
vulnerable: 1.0.0-RC1-incubating ... 2.1.5 (63 versions)
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java …
- CVE-2020-1961CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.1.62020-05-04
vulnerable: 2.1.0 ... 2.1.5 (6 versions)
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (…
- CVE-2025-65998HIGHCVSS 7.5EG 7.5✓ Fixed in 4.0.32025-11-24
vulnerable: 4.0.0, 4.0.1, 4.0.2
Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is configured, the default key value, hard-coded in the source code, is alway…
Check whether org.apache.syncope:syncope-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.syncope:syncope-core CVEs against the assets you own.
Start Free Scan →