CRITICAL
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability
Published May 4, 2020
9.8
CRITICALCVSS 3.1
EPSS 4.98%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.