Impact
A malicious JEXL expression can bypass the JexlContextBuilder name denylist in Apache Syncope, allowing an administrator with Derived Schemas entitlement to create expressions that, when evaluated by another user with User read privileges, expose sensitive LinkedAccount or Manager attributes, including potentially hashed credentials. Because the attacker must be a privileged administrator, the vulnerability is confined to users with existing administrative rights, but any such user can read confidential data they are not normally permitted to see.
Affected Systems
Apache Syncope deployments from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2 are affected. The recommendation is to upgrade to version 4.0.8 or 4.1.3, which contain the fix.
Risk and Exploitability
The CVSS of 4.9 indicates moderate severity. With an EPSS score of less than 1% and no listing in KEV, the likelihood of observed exploitation is low at present. The flaw can be used by any administrator who can create Derived Schemas to craft a JEXL expression; the expression will then be evaluated under a user with read access, allowing the attacker to read sensitive fields. The risk is primarily a confidentiality compromise of data stored in LinkedAccount or Manager objects; the vulnerability does not provide privilege escalation or denial of service beyond data exposure.
OpenCVE Enrichment