Server-Side Template Injection Vulnerability in Apache Syncope
CVE-2020-1961

9.8CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
4 May 2020

Summary

The vulnerability exists in the Mail templates of Apache Syncope, specifically in versions prior to 2.0.15 and 2.1.6. Attackers can exploit this flaw by injecting arbitrary JEXL expressions into the server-side templates, potentially leading to Remote Code Execution. Such exploitation allows unauthorized access and manipulation of the server, emphasizing the necessity for timely updates and security patches to safeguard sensitive data.

Affected Version(s)

Apache Syncope Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.