CVE-2018-1322: Infoleak
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11 and 2.0.x before 2.0.8 can recover sensitive security values using the fiql and orderby parameters.
Other sources
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1322.
What is the severity level of CVE-2018-1322?
CVE-2018-1322 has a severity level of medium (4.9).
Which versions of Apache Syncope are affected by CVE-2018-1322?
Apache Syncope versions 1.2.x (before 1.2.11), 2.0.x (before 2.0.8), and unsupported releases 1.0.x and 1.1.x are affected by CVE-2018-1322.
What is the vulnerability description of CVE-2018-1322?
An administrator with user search entitlements in Apache Syncope can recover sensitive security values using the fiql and orderby parameters.
How can I fix CVE-2018-1322?
To fix CVE-2018-1322, it is recommended to upgrade to Apache Syncope 1.2.11, 2.0.8, or a supported release.