Remote Code Execution Vulnerability in Apache Syncope by Apache
CVE-2020-11977
7.2HIGH
What is CVE-2020-11977?
In Apache Syncope versions prior to 2.1.7, the Flowable extension can be exploited by administrators with proper workflow entitlements. This vulnerability enables performing unauthorized operations through Shell Service Tasks, which include file reading, file writing, and executing arbitrary code. Such actions pose a significant risk to the integrity and confidentiality of the system and its data.
Affected Version(s)
Apache Syncope Apache Syncope 2.1.X releases prior to 2.1.7