syncope.apache.org
http://syncope.apache.org/security.html CVE-2018-1322
MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor in Apache syncope-cope
Record summary
CVE-2018-1322 has a selected CVSS score of 4.9 (medium); EIP currently links 1 catalogued exploit.
Description
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Apache SyncopeBrowse Apache Software Foundation / Apache Syncope | CVE List | Releases prior to 1.2.11, Releases prior to 2.0.8 | affected |
| The unsupported Releases 1.0.x, 1.1.x may be also affected. | affected | ||
org.apache.syncope:syncope-coreBrowse Maven / org.apache.syncope:syncope-core | GitHub Advisory | Before 1.2.11 · Fixed in 1.2.11 | affected |
| 2.0.0 to < 2.0.8 · Fixed in 2.0.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBApache Syncope 2.0.7 - Remote Code ExecutionExploitDB exploitby Che-Chun KuoNot analyzed1 file
References
8103507vdb entry
http://www.securityfocus.com/bid/103507 github.com
https://github.com/advisories/GHSA-v3vf-2r98-xw8w github.com
https://github.com/apache/syncope github.com
https://github.com/apache/syncope/commit/44a5ca0fbd357b8b5d81aa9313fb01cca30d8ad github.com
https://github.com/apache/syncope/commit/735579b6f987b407049ac1f1da08e675d957c3e nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-1322 45400exploit
https://www.exploit-db.com/exploits/45400