AES Encryption Vulnerability in Apache Syncope by Apache
CVE-2025-65998
What is CVE-2025-65998?
Apache Syncope can utilize AES encryption for storing user passwords in its internal database, but this feature is not enabled by default. When activated, it relies on a hard-coded key, which poses a significant risk. If an attacker gains access to the database, they can use this static key to reveal the original plaintext passwords. It's important to note that this issue does not extend to plain attributes that employ AES encryption. To mitigate this risk, it is highly recommended that users upgrade to Apache Syncope versions 3.0.15 or 4.0.3, where the vulnerability is effectively addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Syncope 2.1 <= 2.1.14
Apache Syncope 3.0 <= 3.0.14
Apache Syncope 4.0 <= 4.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved