Impact
The vulnerability exists in Apache Syncope when configured for CAS authentication. The software constructs the target CAS instance URL by blindly trusting forwarded HTTP headers supplied by the client. An attacker can manipulate these headers to inject an arbitrary service URL, causing the Syncope application to redirect end users to an attacker‑controlled site. This is a classic open‑redirect flaw (CWE‑601) that can be leveraged for phishing or other malicious redirects.
Affected Systems
Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. The product is vulnerable until upgraded to version 4.0.8 or 4.1.3, which contain the fix.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is client‑supplied forwarded headers, allowing attackers to manipulate requests via a web browser or crafted HTTP requests. The CVSS score is 6.1, and the EPSS score is < 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA KEV. Despite the lack of quantified metrics, the flaw is exploitable in open‑access scenarios. The impact of an open redirect is to compromise the trust boundary between users and the application, facilitating phishing, credential theft, and session hijacking.
OpenCVE Enrichment