CVE-2014-0111
EPSS 1.4%Apache Syncope JEXL Code Injection
發布日:2022/5/14修改日:2024/11/29
描述
Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."
受影響套件(1)
- Maven/org.apache.syncope:syncope>= 1.0.0, < 1.0.9