Medium severity4.9NVD Advisory· Published Mar 20, 2018· Updated Jun 17, 2026
CVE-2018-1322
CVE-2018-1322
Description
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.syncope:syncope-coreMaven | < 1.2.11 | 1.2.11 |
org.apache.syncope:syncope-coreMaven | >= 2.0.0, < 2.0.8 | 2.0.8 |
Affected products
2- Apache Software Foundation/Apache Syncopev5Range: Releases prior to 1.2.11, Releases prior to 2.0.8
Patches
Vulnerability mechanics
References
8- syncope.apache.org/security.htmlnvdMitigationVendor AdvisoryWEB
- www.securityfocus.com/bid/103507nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-v3vf-2r98-xw8wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1322ghsaADVISORY
- www.exploit-db.com/exploits/45400/nvdThird Party AdvisoryVDB Entry
- github.com/apache/syncope/commit/44a5ca0fbd357b8b5d81aa9313fb01cca30d8adghsaWEB
- github.com/apache/syncope/commit/735579b6f987b407049ac1f1da08e675d957c3eghsaWEB
- www.exploit-db.com/exploits/45400ghsaWEB
News mentions
0No linked articles in our index yet.