Impact
An improper isolation vulnerability in Apache Syncope allows an administrator with sufficient entitlements to create a malicious Groovy class that bypasses the Groovy security sandbox and executes arbitrary server-side code. This flaw is classed as CWE-653 and, if exploited, grants an attacker the ability to run arbitrary code with administrative privileges on the Syncope server. The attack would compromise the confidentiality, integrity, and availability of the entire application and any data it manages.
Affected Systems
Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1 are affected. Users are advised to upgrade to 4.0.7 or 4.1.2 to obtain the fix that tightens the Groovy security sandbox.
Risk and Exploitability
The vulnerability is high risk when a user with administrative entitlements is compromised, and the EPSS score of 0.00439 indicates a very low but non-zero probability of exploitation; the CVSS score of 9.8 underscores its critical severity. The issue is not listed in the CISA KEV catalog. The official fix requires an upgrade to the patched releases; no known public exploits exist at this time, but the impact of successful exploitation would be critical.
OpenCVE Enrichment