Discussion:
[SECURITY] CVE-2014-0111 Apache Syncope
Francesco Chicchiriccò
2014-04-15 07:40:35 UTC
Permalink
CVE-2014-0111: Remote code execution by an authenticated administrator

Severity: Important

Vendor:
The Apache Software Foundation

Versions Affected:
Syncope 1.0.0 to 1.0.8
Syncope 1.1.0 to 1.1.6

Description:
In the various places in which Apache Commons JEXL expressions are
allowed (derived schema definition, user / role templates, account links
of resource mappings) a malicious administrator can inject Java code
that can be executed remotely by the JEE container running the Apache
Syncope core.

Credit:
This issue was discovered by Grégory Draperi.

References:
http://syncope.apache.org/security.html

Loading...