[SECURITY] CVE-2014-0111 Apache Syncope
Francesco Chicchiriccò <[email protected]> Tue, 15 Apr 2014 09:40:35 +0200
| Newsgroups | gmane.comp.security.bugtraq,gmane.comp.jakarta.lucene.net.user,gmane.comp.apache.incubator.bigtop.devel,gmane.comp.apache.maven.announce,gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 CVE-2014-0111: Remote code execution by an authenticated administrator Severity: Important Vendor: The Apache Software Foundation Versions Affected: Syncope 1.0.0 to 1.0.8 Syncope 1.1.0 to 1.1.6 Description: In the various places in which Apache Commons JEXL expressions are=20 allowed (derived schema definition, user / role templates, account links=20 of resource mappings) a malicious administrator can inject Java code=20 that can be executed remotely by the JEE container running the Apache=20 Syncope core. Credit: This issue was discovered by Gr=E9gory Draperi. References: http://syncope.apache.org/security.html -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQEcBAEBAgAGBQJTTOJyAAoJEGtDE+0nPfKHxWcIAI9POTzr4bIF7fXO25uXgfny BO8SR0fmGScdmeohf8nQZbUNgKA1F7YRe5vC9r8nKFSpdDJrMnPSTOwMYrgdOxHt Rl/SpEab4b8NX0FO1a6TObDbXBDj+Q+4cNUXOOc0jC7lU67n1SorfGaMbjLfcZ0w 2xnZsbAQ0P0bmIJ2mR+LuXLsEA3kwvClF9fUTEDlJ4Rm/yT16UGvD5+vEJdMQzen JhBdT8VeX4wvtYr9+WmmWqeWgvSmezE07s5Pu36qXkxAEFGzdQBtJ/XJbpbgM7Sa 7MoZQHQqJ5VwUVGMseqcxhAjD065uHP41HpAeF4TFQvp4jg8/FiybFdXqiJ+smI=3D =3D4XQi -----END PGP SIGNATURE-----