Vulnerabilities > Apache > Syncope > 2.1.6

DATE CVE VULNERABILITY TITLE RISK
2024-07-22 CVE-2024-38503 Unspecified vulnerability in Apache Syncope
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.
network
low complexity
apache
5.4
2020-09-15 CVE-2020-11977 Unspecified vulnerability in Apache Syncope
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.
network
low complexity
apache
7.2