Apache Syncope是美国阿帕奇(Apache)基金会的一套用于企业环境中的开源数字身份管理系统。该系统支持身份管理、角色配置等。 Apache Syncope 3.0版本至3.0.16版本、4.0版本至4.0.5版本和4.1.0版本存在安全漏洞,该漏洞源于通过数据查询暴露敏感信息,可能导致具有足够权限的管理员创建恶意JEXL表达式,从而访问用户相关的安全敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Syncope | 3.0≤ 3.0.16 |
affected |
4.0≤ 4.0.5 |
affected | ||
4.1≤ 4.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Syncope | 3.0 ~ 3.0.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48589 | Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow | |
| CVE-2026-44598 | Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials) | |
| CVE-2026-43828 | Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by | |
| CVE-2026-43827 | Apache Shiro: Session fixation: new session is not created after login by default | |
| CVE-2026-42782 | Apache Syncope: Post-auth RCE via Groovy static | |
| CVE-2026-46745 | Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reacha | |
| CVE-2026-45361 | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook | |
| CVE-2026-45249 | Apache ECharts: XSS in Lines series tooltip rendering |
No comments yet