Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/Apache Software Foundation/org.apache.syncope.core:syncope-core-spring

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Join the discussion

Apache Syncope versions 3.0.15 through 3.0.16, 4.0.3 through 4.0.7, and 4.1.0-M0 through 4.1.2 contain a vulnerability where sensitive information, specifically the AES key after padding, is inserted into log files. This occurs when a non-standard length AES key is configured, causing Syncope to pad the key with random characters and log the resulting value. Upgrading to versions 4.0.8 or 4.1.3 addresses this issue.

Join the discussion

Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 contain an authentication bypass vulnerability due to spoofing. This occurs when JWKS settings for internal JWT authentication are disclosed, allowing an attacker who has authenticated successfully and obtained a valid JWT to spoof another user's privileges. Upgrading to versions 4.0.8 or 4.1.3 resolves this issue.

Join the discussion

Apache Syncope contains an improper isolation vulnerability allowing an administrator with Implementation entitlements to create malicious Groovy classes that bypass the Groovy security sandbox. This affects versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. The issue is fixed in versions 4.0.7 and 4.1.2 by tightening the Groovy sandbox.

Join the discussion

Apache Syncope versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0 contain an improper isolation vulnerability. An administrator with sufficient privileges can create malicious Groovy code that executes outside the intended sandbox, including static initializers. This can lead to unauthorized code execution with high impact on confidentiality, integrity, and availability. Fixed versions 4.0.6 and 4.1.1 enforce sandboxing even for static initializers in Groovy code.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:maven/Apache Software Foundation/org.apache.syncope.core:syncope-core-spring
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses