Apache Syncope Vulnerabilities Allow Attackers to Execute Malicious Code and Bypass Controls

Apache Syncope has disclosed three important security vulnerabilities that could allow authorized administrators to execute malicious SQL commands, bypass Groovy sandbox protections, and impersonate higher-privileged users. The issues affect several Apache Syncope 3.0, 4.0, and 4.1 releases and have been fixed in versions 4.0.8 and 4.1.3. Apache Syncope is an open-source identity management and access […]

This article has been indexed from Cyber Security News

Read the original article: