Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
Vulnerability Description
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.
CVSS Information
N/A
Vulnerability Type
不充分的划分
Vulnerability Title
Apache Syncope 权限许可和访问控制问题漏洞
Vulnerability Description
Apache syncope是美国Apache基金会开源的一套身份管理自动化工具。 Apache Syncope 3.0.0-M0至3.0.16版本、4.0.0-M0至4.0.6版本、4.1.0-M0至4.1.1版本存在权限许可和访问控制问题漏洞,该漏洞源于隔离或分区化不当,管理员可通过REST API导入任意BPMN流程定义并启动,当包含Groovy scriptTask的BPMN流程被导入和启动时,Groovy脚本直接在服务器上执行且没有沙箱保护。
CVSS Information
N/A
Vulnerability Type
N/A