Impact
Audit events in Apache Syncope are recorded without masking sensitive information, allowing administrators to view cleartext credentials or other secrets that are attached to audit payloads. This flaw falls under CWE-522, indicating that credentials are not adequately protected during storage or transportation. The primary consequence is the exposure of confidential data to anyone with administrative access to the audit store, potentially facilitating credential theft or further compromise of systems that rely on those credentials.
Affected Systems
Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 are vulnerable. Users of these releases should verify their version and plan a migration to a supported release.
Risk and Exploitability
The CVSS score of 4.9 reflects moderate risk primarily due to the requirement for administrator-level access to read audit logs. The EPSS score is <1%, and the vulnerability is not listed in CISA KEV, indicating no known active exploits at this time. The attack vector is inferred to be local or sub‑network based, relying on legitimate administrative privileges to retrieve unmasked audit records.
OpenCVE Enrichment