Impact
An administrator with sufficient entitlements can use the REST interface to enumerate existing access tokens, retrieving their signed JWT bodies. These tokens can then be leveraged to issue further REST requests, effectively allowing an attacker to impersonate users with higher administrative rights. The vulnerability therefore exposes sensitive information and enables unauthorized elevation of privilege and impersonation.
Affected Systems
Apache Syncope is affected across multiple milestone releases. Versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 all contain the flaw. Users of these releases are at risk until they upgrade to the patched versions.
Risk and Exploitability
Because the flaw relies on privileged REST access, it requires the attacker to have, or gain, suitable administrative credentials. Once an admin role is obtained, the endpoint that lists access tokens can be exploited without additional conditions; the attacker can then copy the signed JWT and issue authenticated requests as a more privileged user. The EPSS score is unavailable and the vulnerability is not present in the CISA KEV catalog, but the potential for privilege escalation and identity theft suggests a high risk. No CVSS score is reported; however, the severity is likely substantial given the scope of impact.
OpenCVE Enrichment