We found results for “”
CVE-2018-1322
Good to know:
Date: March 20, 2018
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
Language: Java
Severity Score
Related Resources (10)
Severity Score
Weakness Type (CWE)
Information Leak / Disclosure
CWE-200Top Fix
Upgrade Version
Upgrade to version org.apache.syncope.core:syncope-core-persistence-jpa:2.0.8;org.apache.syncope.ext.elasticsearch:syncope-ext-elasticsearch-persistence-jpa:2.0.8;org.apache.syncope.common:syncope-common-lib:2.0.8;org.apache.syncope:syncope-core:1.2.11;org.apache.syncope:syncope-common:1.2.11
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | HIGH |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | SINGLE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |