Impact
When a non‑standard AES key length is configured, Syncope pads the user‑supplied key with random characters and logs the resulting padded value, thereby exposing a cryptographic secret. This vulnerability exposes an otherwise confidential key, potentially allowing an attacker to decrypt data protected by that key.
Affected Systems
Apache Syncope versions 3.0.15 through 3.0.16, 4.0.3 through 4.0.7, and 4.1.0‑M0 through 4.1.2 distributed by the Apache Software Foundation are affected.
Risk and Exploitability
The CVSS score of 7.5 indicates substantial impact, yet the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would need read access to the application log files, which typically requires local or privileged access. The impact is limited to the exposure of the AES key, which could be leveraged to compromise data protected by that key if it is reused elsewhere.
OpenCVE Enrichment