漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Syncope: RCE via Groovy Sandbox bypass
Vulnerability Description
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security sandbox.
CVSS Information
N/A
Vulnerability Type
不充分的划分
Vulnerability Title
Apache Syncope 权限许可和访问控制问题漏洞
Vulnerability Description
Apache syncope是美国Apache基金会开源的一套身份管理自动化工具。 Apache Syncope 3.0.0-M0版本至3.0.16版本、4.0.0-M0版本至4.0.6版本和4.1.0-M0版本至4.1.1版本存在权限许可和访问控制问题漏洞,该漏洞源于隔离或分区化不当,可能导致具有足够权限的管理员创建包含未信任代码的恶意Groovy类,从而绕过Groovy安全沙箱。
CVSS Information
N/A
Vulnerability Type
N/A