https://seclists.org/oss-sec/2024/q4/39: CVE-2024-45031: Apache Syncope: Stod XSS in Console and Enduser
Published Oct 24, 2024
·Updated
Affected Software
1 affected component
Apache Syncope>=2.1<2.1.15, >=3.0<3.0.9
Frequently Asked Questions
1
What is the severity of CVE-2024-45031?
The severity of CVE-2024-45031 is classified as moderate.
2
What versions of Apache Syncope are affected by CVE-2024-45031?
Apache Syncope versions 2.1 through 2.1.14 and 3.0 through 3.0.8 are affected by CVE-2024-45031.
3
What is the primary issue addressed by CVE-2024-45031?
CVE-2024-45031 addresses the risk of stored XSS attacks due to incomplete HTML tags bypassing sanitization in the Syncope Console.
4
How can I fix CVE-2024-45031?
To fix CVE-2024-45031, upgrade to Apache Syncope version 2.1.15 or 3.0.9 or later.
5
What potential impact does CVE-2024-45031 have on applications?
CVE-2024-45031 can lead to stored XSS vulnerabilities that could compromise user data and session integrity in applications using affected versions.