Apache Software Foundation Syncope 3.0.9

CPE Details

Apache Software Foundation Syncope 3.0.9
3.0.9
2025-07-16
14h23 +00:00
2025-07-16
14h23 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:syncope:3.0.9:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

syncope

Version

3.0.9

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-57738 2025-10-20 13h15 +00:00 Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.
7.2
High