Impact
Improper verification of cryptographic signatures in Apache Syncope’s Service Resource Adapter (SRA) when configured for OAuth 2.0 without a JWKS set URI allows an attacker to forge JSON Web Tokens (JWTs). The forged tokens can impersonate any user identity and grant the attacker the same permissions that the legitimate user would have, effectively bypassing authentication. This weakness is identified as CWE‑347 and creates a critical authentication bypass that can lead to full control over services proxied by SRA.
Affected Systems
Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. These ranges include all milestone and initial release builds of the 3.x, 4.0.x, and 4.1.x series. The issue does not appear in versions prior to 3.0.0‑M0 or in 4.0.8 and later, 4.1.3 and later.
Risk and Exploitability
Because the flaw allows an unauthenticated attacker to create a valid JWT when SRA is misconfigured, the risk is high and the potential impact includes unauthorized full access to all services protected by SRA. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only access to the OAuth 2.0 configuration or the service endpoint to craft a malicious token; no additional privileges or local access are required. Given the severity and the lack of known mitigation until patching, administrators should treat this as a high‑risk issue and prioritize remediation.
OpenCVE Enrichment