Apache syncope是美国Apache基金会开源的一套身份管理自动化工具。 Apache Syncope 3.0.0-M0至3.0.16版本、4.0.0-M0至4.0.6版本和4.1.0-M0至4.1.1版本存在服务端请求伪造漏洞,该漏洞源于Connectors和Resources检查功能存在服务端请求伪造漏洞,可能导致低权限认证用户利用此漏洞进行服务端请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Syncope | 3.0.0-M0≤ 3.0.16 |
affected |
4.0.0-M0≤ 4.0.6 |
affected | ||
4.1.0-M0≤ 4.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Syncope | 3.0.0-M0 ~ 3.0.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56452 | 7.5 HIGH | Apache MINA SSHD: Path traversal in SCP file reception |
| CVE-2026-56624 | 7.3 HIGH | Apache MINA SSHD: SSH certificate options lack validations |
| CVE-2026-56623 | 7.1 HIGH | Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows |
| CVE-2026-58624 | 5.4 MEDIUM | Apache MINA SSHD: Remote execution of JGit commands can write files on the server |
| CVE-2026-63071 | Apache Syncope: RCE via Groovy Sandbox bypass | |
| CVE-2026-53405 | Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask | |
| CVE-2026-53421 | Apache Syncope: Remote Code Execution via Scripted Connector | |
| CVE-2026-57308 | Apache Syncope: SQL injection vulnerability in Audit Events search | |
| CVE-2026-62183 | Apache Syncope: User self-service privilege escalation |
No comments yet