Impact
Low‑privileged authenticated Server‑Side Request Forgery in Apache Syncope allows an attacker with limited user rights to cause the server to make arbitrary network requests through its Connectors and Resources check, potentially exposing internal resources or exfiltrating data. The weakness is identified as CWE‑918 and can undermine confidentiality and internal network isolation. The flaw requires authentication but does not need elevated privileges, making it possible for any authenticated user to exploit.
Affected Systems
Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.6, and 4.1.0‑M0 through 4.1.1 are affected, while upgrading to 4.0.7 or 4.1.2 removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, yet the EPSS score of below 1% suggests a low likelihood of exploitation in the near term. However, the ability to force the server to reach any endpoint that Syncope can access poses a serious risk of internal network exposure and data leakage. The vulnerability is not listed in CISA KEV, so organizations should treat it as a high‑risk flaw until patched.
OpenCVE Enrichment