[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[SECURITY] CVE-2014-0111 Apache Syncope
- To: gregory draperi <gregory.draperi@xxxxxxxxx>, user@xxxxxxxxxxxxxxxxxx, dev@xxxxxxxxxxxxxxxxxx, announce@xxxxxxxxxx, "security@xxxxxxxxxx" <security@xxxxxxxxxx>, full-disclosure@xxxxxxxxxxxxxxxxx, bugtraq@xxxxxxxxxxxxxxxxx
- Subject: [SECURITY] CVE-2014-0111 Apache Syncope
- From: Francesco Chicchiriccò <ilgrosso@xxxxxxxxxx>
- Date: Tue, 15 Apr 2014 09:40:35 +0200
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
CVE-2014-0111: Remote code execution by an authenticated administrator
Severity: Important
Vendor:
The Apache Software Foundation
Versions Affected:
Syncope 1.0.0 to 1.0.8
Syncope 1.1.0 to 1.1.6
Description:
In the various places in which Apache Commons JEXL expressions are
allowed (derived schema definition, user / role templates, account links
of resource mappings) a malicious administrator can inject Java code
that can be executed remotely by the JEE container running the Apache
Syncope core.
Credit:
This issue was discovered by Grégory Draperi.
References:
http://syncope.apache.org/security.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQEcBAEBAgAGBQJTTOJyAAoJEGtDE+0nPfKHxWcIAI9POTzr4bIF7fXO25uXgfny
BO8SR0fmGScdmeohf8nQZbUNgKA1F7YRe5vC9r8nKFSpdDJrMnPSTOwMYrgdOxHt
Rl/SpEab4b8NX0FO1a6TObDbXBDj+Q+4cNUXOOc0jC7lU67n1SorfGaMbjLfcZ0w
2xnZsbAQ0P0bmIJ2mR+LuXLsEA3kwvClF9fUTEDlJ4Rm/yT16UGvD5+vEJdMQzen
JhBdT8VeX4wvtYr9+WmmWqeWgvSmezE07s5Pu36qXkxAEFGzdQBtJ/XJbpbgM7Sa
7MoZQHQqJ5VwUVGMseqcxhAjD065uHP41HpAeF4TFQvp4jg8/FiybFdXqiJ+smI=
=4XQi
-----END PGP SIGNATURE-----