Apache syncope是美国Apache基金会开源的一套身份管理自动化工具。 Apache Syncope 3.0.0-M0至3.0.16版本、4.0.0-M0至4.0.6版本、4.1.0-M0至4.1.1版本存在权限许可和访问控制问题漏洞,该漏洞源于隔离或分区化不当,管理员可通过REST API导入任意BPMN流程定义并启动,当包含Groovy scriptTask的BPMN流程被导入和启动时,Groovy脚本直接在服务器上执行且没有沙箱保护。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Syncope | 3.0.0-M0≤ 3.0.16 |
affected |
4.0.0-M0≤ 4.0.6 |
affected | ||
4.1.0-M0≤ 4.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Syncope | 3.0.0-M0 ~ 3.0.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56452 | 7.5 HIGH | Apache MINA SSHD: Path traversal in SCP file reception |
| CVE-2026-56624 | 7.3 HIGH | Apache MINA SSHD: SSH certificate options lack validations |
| CVE-2026-56623 | 7.1 HIGH | Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows |
| CVE-2026-58624 | 5.4 MEDIUM | Apache MINA SSHD: Remote execution of JGit commands can write files on the server |
| CVE-2026-63071 | Apache Syncope: RCE via Groovy Sandbox bypass | |
| CVE-2026-53421 | Apache Syncope: Remote Code Execution via Scripted Connector | |
| CVE-2026-57308 | Apache Syncope: SQL injection vulnerability in Audit Events search | |
| CVE-2026-62183 | Apache Syncope: User self-service privilege escalation | |
| CVE-2026-62418 | Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check |
No comments yet