Server-Side Template Injection Vulnerability in Apache Syncope
CVE-2020-1961
9.8CRITICAL
Summary
The vulnerability exists in the Mail templates of Apache Syncope, specifically in versions prior to 2.0.15 and 2.1.6. Attackers can exploit this flaw by injecting arbitrary JEXL expressions into the server-side templates, potentially leading to Remote Code Execution. Such exploitation allows unauthorized access and manipulation of the server, emphasizing the necessity for timely updates and security patches to safeguard sensitive data.
Affected Version(s)
Apache Syncope Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved