Impact
An authenticated user can query the list of OpenID Connect providers configured for Apache Syncope’s SSO console and end‑user interfaces. The API response contains the full configuration for each provider, including client secrets, regardless of the caller’s entitlement. Consequently, sensitive credentials are exposed to any user who can log into Syncope, allowing an attacker to recover secrets that could be used to forge authentication tokens or compromise downstream services that rely on those providers.
Affected Systems
The vulnerability affects Apache Software Foundation’s Apache Syncope. Versions from 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are vulnerable. The fix is included in version 4.0.8 and 4.1.3, which should be used for remediation.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is less than 1%, suggesting low likelihood of public exploitation to date. However, because the attacker only needs to be an authenticated Syncope user, the risk remains significant for organizations that provide broad console access without further checks. The disclosure of client secrets could be leveraged to impersonate OAuth clients or to compromise applications that rely on the same identity provider.
OpenCVE Enrichment