icon

We found results for “

CVE-2025-57738

Good to know:

icon
icon

Date: October 20, 2025

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Isolation or Compartmentalization

CWE-653

Top Fix

icon

Upgrade Version

Upgrade to version org.apache.syncope.core:syncope-core-spring:no_fix;org.apache.syncope.core:syncope-core-spring:3.0.14;org.apache.syncope.core:syncope-core-spring:4.0.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us