Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
Update org.apache.syncope.core:syncope-core-spring to 4.0.6; org.apache.syncope.core:syncope-core-spring to 4.1.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Syncope has an Improper Isolation or Compartmentalization vulnerability affects org.apache.syncope.core:syncope-core-spring (maven), org.apache.syncope.core:syncope-core-spring (maven), org.apache.syncope.core:syncope-core-spring (maven). Severity is high. Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
Update org.apache.syncope.core:syncope-core-spring to 4.0.6; org.apache.syncope.core:syncope-core-spring to 4.1.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Syncope has an Improper Isolation or Compartmentalization vulnerability affects org.apache.syncope.core:syncope-core-spring (maven), org.apache.syncope.core:syncope-core-spring (maven), org.apache.syncope.core:syncope-core-spring (maven). Severity is high. Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.syncope.core:syncope-core-springmaven |
|---|
| >=3.0.0-M0,<=3.0.16 |
| Not reported |
| org.apache.syncope.core:syncope-core-springmaven | >=4.0.0-M0,<4.0.6 | 4.0.6 |
|---|
| org.apache.syncope.core:syncope-core-springmaven | >=4.1.0-M0,<4.1.1 | 4.1.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| org.apache.syncope.core:syncope-core-springmaven |
|---|
| >=3.0.0-M0,<=3.0.16 |
| Not reported |
| org.apache.syncope.core:syncope-core-springmaven | >=4.0.0-M0,<4.0.6 | 4.0.6 |
|---|
| org.apache.syncope.core:syncope-core-springmaven | >=4.1.0-M0,<4.1.1 | 4.1.1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard