VYPR

Syncope

by Apache

Source repositories

CVEs (46)

  • CVE-2020-11977HigSep 15, 2020
    risk 0.47cvss 7.2epss 0.03

    In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.

  • CVE-2026-23794MedFeb 3, 2026
    risk 0.44cvss 6.8epss 0.00

    Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through…

  • CVE-2018-1321HigMar 20, 2018
    risk 0.44cvss 7.2epss 0.17

    An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to…

  • CVE-2026-77147MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their CommandArgs static…

  • CVE-2025-65998HigNov 24, 2025
    risk 0.42cvss 7.5epss 0.01

    Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is configured, the default key value, hard-coded in the source code, is always used. This allows a malicious…

  • CVE-2025-57738HigOct 20, 2025
    risk 0.42cvss 7.2epss 0.23

    Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly…

  • CVE-2026-73191MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers. This…

  • CVE-2026-78318MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HTML tags with unsafe JS inline, via…

  • CVE-2018-17186HigNov 6, 2018
    risk 0.40cvss 7.2epss 0.02

    An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.

  • CVE-2018-17184MedNov 6, 2018
    risk 0.35cvss 5.4epss 0.01

    A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the…

  • CVE-2024-45031MedOct 24, 2024
    risk 0.33cvss 6.1epss 0.01

    When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in…

  • CVE-2026-77883MedSep 14, 2026
    risk 0.32cvss 4.9epss 0.00

    Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access…

  • CVE-2026-75015MedSep 14, 2026
    risk 0.32cvss 4.9epss 0.00

    Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values. …

  • CVE-2026-42797MedMay 25, 2026
    risk 0.32cvss 4.9epss 0.00

    Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access…

  • CVE-2026-23795MedFeb 3, 2026
    risk 0.32cvss 4.9epss 0.02

    Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data…

  • CVE-2018-1322MedMar 20, 2018
    risk 0.30cvss 4.9epss 0.21

    An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.

  • CVE-2024-38503MedJul 22, 2024
    risk 0.28cvss 5.4epss 0.01

    When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are…

  • CVE-2019-17557MedMay 4, 2020
    risk 0.28cvss 5.4epss 0.01

    It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.

  • CVE-2026-63071CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope:…

  • CVE-2026-62418HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are…