First published: Tue Mar 20 2018(Updated: )
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11 and 2.0.x before 2.0.8 can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Syncope | >=1.2.0<1.2.11 | |
Apache Syncope | >=2.0.0<2.0.8 | |
Apache Syncope | =1.0.0 | |
Apache Syncope | =1.0.4 | |
Apache Syncope | =1.0.5 | |
Apache Syncope | =1.0.6 | |
Apache Syncope | =1.0.7 | |
Apache Syncope | =1.0.8 | |
Apache Syncope | =1.0.9 | |
Apache Syncope | =1.1.0 | |
Apache Syncope | =1.1.1 | |
Apache Syncope | =1.1.2 | |
Apache Syncope | =1.1.3 | |
Apache Syncope | =1.1.4 | |
Apache Syncope | =1.1.5 | |
Apache Syncope | =1.1.6 | |
Apache Syncope | =1.1.7 | |
Apache Syncope | =1.1.8 | |
Apache Syncope | =1.2.0-milestone1 | |
maven/org.apache.syncope:syncope-core | >=2.0.0<2.0.8 | 2.0.8 |
maven/org.apache.syncope:syncope-core | <1.2.11 | 1.2.11 |
>=1.2.0<1.2.11 | ||
>=2.0.0<2.0.8 | ||
=1.0.0 | ||
=1.0.4 | ||
=1.0.5 | ||
=1.0.6 | ||
=1.0.7 | ||
=1.0.8 | ||
=1.0.9 | ||
=1.1.0 | ||
=1.1.1 | ||
=1.1.2 | ||
=1.1.3 | ||
=1.1.4 | ||
=1.1.5 | ||
=1.1.6 | ||
=1.1.7 | ||
=1.1.8 | ||
=1.2.0-milestone1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1321 is a vulnerability in Apache Syncope that allows an administrator with report and template entitlements to perform malicious operations, including file read and write, using XSL Transformations (XSLT).
An administrator can exploit CVE-2018-1321 by using XSL Transformations (XSLT) to perform malicious operations, such as file read and write.
Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x are affected by CVE-2018-1321.
CVE-2018-1321 has a severity rating of 7.2, indicating a high severity.
Yes, you can find references for CVE-2018-1321 at the following URLs: [http://syncope.apache.org/security.html#CVE-2018-1321:_Remote_code_execution_by_administrators_with_report_and_template_entitlements](http://syncope.apache.org/security.html#CVE-2018-1321:_Remote_code_execution_by_administrators_with_report_and_template_entitlements), [http://www.securityfocus.com/bid/103508](http://www.securityfocus.com/bid/103508), [https://www.exploit-db.com/exploits/45400/](https://www.exploit-db.com/exploits/45400/)