When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.
History

Fri, 06 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Wed, 11 Sep 2024 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Wed, 11 Sep 2024 11:15:00 +0000

Type Values Removed Values Added
References

Tue, 10 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Weaknesses CWE-79
CPEs cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache syncope
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-07-22T09:46:39.285Z

Updated: 2024-12-06T21:48:36.234Z

Reserved: 2024-06-18T08:50:18.444Z

Link: CVE-2024-38503

cve-icon Vulnrichment

Updated: 2024-08-02T04:12:25.158Z

cve-icon NVD

Status : Modified

Published: 2024-07-22T10:15:08.723

Modified: 2024-12-06T22:15:19.420

Link: CVE-2024-38503

cve-icon Redhat

No data.