Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check
Vulnerability Description
Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
CVSS Information
N/A
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Apache Syncope 服务端请求伪造漏洞
Vulnerability Description
Apache syncope是美国Apache基金会开源的一套身份管理自动化工具。 Apache Syncope 3.0.0-M0至3.0.16版本、4.0.0-M0至4.0.6版本和4.1.0-M0至4.1.1版本存在服务端请求伪造漏洞,该漏洞源于Connectors和Resources检查功能存在服务端请求伪造漏洞,可能导致低权限认证用户利用此漏洞进行服务端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A