#apachesyncope
@bsky.hfcoma.de ich weiß nicht ob es (komplett) FOSS ist, aber definitiv OSS.
ApacheSyncope mit OpenLDAP als IDM und eduMFA für 2FA.
November 7, 2025 at 11:11 AM
Critical flaw in #ApacheSyncope allows attackers to decrypt user passwords via hardcoded encryption key. Immediate upgrade to versions 3.0.15 or 4.0.3 recommended. #CyberSecurity #DataBreach Link: thedailytechfeed.com/vulnerabilit...
November 26, 2025 at 6:41 PM
Syncope 3.0-4.1 had SQL, sandbox & JWT flaws letting admins escalate access—upgrade to 4.0.8/4.1.3 now. #SecurityNews #IdentityManagement #ApacheSyncope #CVE2026 #JWT #SQLInjection thedailytechfeed.com/apache-synco...
September 16, 2026 at 1:48 PM
CVE-2026-82232 - apache syncope
If an administrator with sufficient rights uses the task‑search feature, they can insert specially crafted sorting instructions that cause the system to execute…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-82232: Apache Syncope allows admins to run unauthorized database commands
If an administrator with sufficient rights uses the task‑search feature, they can insert specially crafted sorting instructions that cause the system to.
stackflag.com
September 14, 2026 at 8:40 PM
CVE-2026-87785 - apache syncope
Certain versions of Apache Syncope (3.0.0‑M0 through 3.0.16 and 4.0.0‑M0 through 4.1.2) can expose the settings used to verify internal login tokens. If an…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-87785: Apache Syncope allows attackers to impersonate users
Certain versions of Apache Syncope (3.0.0‑M0 through 3.0.16 and 4.0.0‑M0 through 4.1.2) can expose the settings used to verify internal login tokens.
stackflag.com
September 14, 2026 at 8:30 PM
CVE-2026-77051 - apache syncope
In certain versions of Apache Syncope, an admin with proper rights can insert malicious input that makes the system execute any database command. This could let…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-77051: Apache Syncope lets admin run unauthorized database commands
In certain versions of Apache Syncope, an admin with proper rights can insert malicious input that makes the system execute any database command.
stackflag.com
September 14, 2026 at 9:10 PM
CVE-2026-87802 - apache syncope
Apache Syncope versions from 3.0.0‑M0 to 4.1.2 can accept forged authentication tokens when OAuth 2.0 is set up without a proper key source. An attacker could…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-87802: Apache Syncope OAuth mis-checks signatures, allowing impersonation
Apache Syncope versions from 3.0.0‑M0 to 4.1.2 can accept forged authentication tokens when OAuth 2.0 is set up without a proper key source.
stackflag.com
September 14, 2026 at 8:30 PM
CVE-2026-73579 - apache syncope
Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2 can omit permission checks on certain search queries, allowing users to see information they shouldn’t.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-73579: Apache Syncope may expose data to unauthorized users
Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2 can omit permission checks on certain search queries, allowing users to see information they shouldn’t.
stackflag.com
September 14, 2026 at 8:50 PM
CVE-2026-73370 - apache syncope
Versions of Apache Syncope up to 3.16, 4.0.7, and 4.1.2 may let an administrator use a data‑sync feature to perform actions in parts of the system they are not…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-73370: Apache Syncope lets admins act beyond their rights
Versions of Apache Syncope up to 3.16, 4.0.7, and 4.1.2 may let an administrator use a data‑sync feature to perform actions in parts of the system they.
stackflag.com
September 14, 2026 at 9:00 PM
CVE-2026-73668 - apache syncope
In certain versions of Apache Syncope, an administrator who has rights in one area could use the REST interface to see the full configuration of connectors…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-73668: Apache Syncope admin can view other realm connector settings
In certain versions of Apache Syncope, an administrator who has rights in one area could use the REST interface to see the full configuration of.
stackflag.com
September 14, 2026 at 9:00 PM
CVE-2026-77181 - apache syncope
In Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2, the system checks the wrong permission when changing a ClientApp, allowing users who can only create a…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-77181: Apache Syncope may let unauthorized updates to client apps
In Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2, the system checks the wrong permission when changing a ClientApp, allowing users who can only.
stackflag.com
September 14, 2026 at 7:30 PM
CVE-2026-75030 - apache syncope
In Apache Syncope versions up to 3.0.16, 4.0.7, and 4.1.2, an administrator who is only allowed to run tasks can add or remove large numbers of users from…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-75030: Apache Syncope admins could change many group members
In Apache Syncope versions up to 3.0.16, 4.0.7, and 4.1.2, an administrator who is only allowed to run tasks can add or remove large numbers of users from.
stackflag.com
September 14, 2026 at 9:10 PM
CVE-2026-86460 - apache syncope
Versions of Apache Syncope from 3.0.0‑M0 to 3.0.16, 4.0.0‑M0 to 4.0.7, and 4.1.0‑M0 to 4.1.2 let specially formed search queries run commands on the Neo4j…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-86460: Apache Syncope crafted search can execute database commands
Versions of Apache Syncope from 3.0.0‑M0 to 3.0.16, 4.0.0‑M0 to 4.0.7, and 4.1.0‑M0 to 4.1.2 let specially formed search queries run commands on the Neo4j.
stackflag.com
September 14, 2026 at 8:40 PM
CVE-2026-78330 - apache syncope
Versions of Apache Syncope from 3.0.0‑M0 up to 3.0.16, and from 4.0.0‑M0 through 4.1.2, may let an attacker who has a normal user’s login token obtain full…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-78330: Apache Syncope can grant admin rights via login token
Versions of Apache Syncope from 3.0.0‑M0 up to 3.0.16, and from 4.0.0‑M0 through 4.1.2, may let an attacker who has a normal user’s login token obtain.
stackflag.com
September 14, 2026 at 7:30 PM
CVE-2026-73470 - apache syncope
In versions of Apache Syncope from 3.0.0-M0 up to 4.1.2, a user who is given delegation rights can grant roles they do not own or that belong to a different…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-73470: Apache Synapse lets delegated users assign unauthorized roles
In versions of Apache Syncope from 3.0.0-M0 up to 4.1.2, a user who is given delegation rights can grant roles they do not own or that belong to a.
stackflag.com
September 14, 2026 at 8:50 PM
CVE-2026-63071 - apache syncope
An administrator can accidentally or intentionally create malicious code in Apache Syncope, potentially allowing unauthorized actions. This affects versions…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-63071: Apache Syncope: Malicious Code Can Be Injected
An administrator can accidentally or intentionally create malicious code in Apache Syncope, potentially allowing unauthorized actions.
stackflag.com
July 21, 2026 at 3:30 PM
CVE-2026-62183 - apache syncope
Apache Syncope, a user management tool, has a security issue that allows unprivileged users to gain administrator privileges. This could happen if a user is…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-62183: Apache Syncope: Unprivileged Users Can Gain Admin Access
Apache Syncope, a user management tool, has a security issue that allows unprivileged users to gain administrator privileges.
stackflag.com
July 21, 2026 at 3:34 PM
CVE-2026-53405 - apache syncope
Apache Syncope, a user management system, allows an administrator to import and run custom scripts on the server. This can lead to malicious scripts being…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-53405: Apache Syncope: Malicious Scripts Can Run on Server
Apache Syncope, a user management system, allows an administrator to import and run custom scripts on the server.
stackflag.com
July 21, 2026 at 3:32 PM
CVE-2026-57308 - apache syncope
Apache Syncope, a user identity management tool, has a security flaw that allows an administrator with proper access to execute unauthorized SQL code. This…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-57308: Apache Syncope SQL Injection Risk: Unauthorized Code Execution
Apache Syncope, a user identity management tool, has a security flaw that allows an administrator with proper access to execute unauthorized SQL code.
stackflag.com
July 21, 2026 at 3:34 PM
CVE-2026-53421 - apache syncope
Apache Syncope, a user identity management system, has a security flaw that allows an authorized administrator to execute malicious code remotely. This could…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-53421: Apache Syncope Remote Code Execution via Scripted Connectors
Apache Syncope, a user identity management system, has a security flaw that allows an authorized administrator to execute malicious code remotely.
stackflag.com
July 21, 2026 at 3:32 PM
Critical RCE vulnerability found in Apache Syncope's Groovy scripting (CVE-2025-57738). Immediate upgrade to versions 3.0.14 or 4.0.2 recommended. #CyberSecurity #ApacheSyncope #RCE Link: thedailytechfeed.com/critical-rem...
October 22, 2025 at 9:42 AM
🤦 #ApacheSyncope uses a default, hard-coded key when admins select “AES password encryption”. This allows attackers with a copy of the encrypted password DB to use this publicly-available key to decrypt every password stored. Fixes in 3.0.15 and 4.0.3, and a backported fix for 2.1.x available. 🧵3/5
December 1, 2025 at 8:11 PM