Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
Update org.apache.syncope.core:syncope-core-provisioning-api to 4.0.6; org.apache.syncope.core:syncope-core-provisioning-api to 4.1.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Syncope Vulnerable to Exposure of Sensitive Information Through Data Queries affects org.apache.syncope.core:syncope-core-provisioning-api (maven), org.apache.syncope.core:syncope-core-provisioning-api (maven), org.apache.syncope.core:syncope-core-provisioning-api (maven). Severity is medium. Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
Update org.apache.syncope.core:syncope-core-provisioning-api to 4.0.6; org.apache.syncope.core:syncope-core-provisioning-api to 4.1.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Syncope Vulnerable to Exposure of Sensitive Information Through Data Queries affects org.apache.syncope.core:syncope-core-provisioning-api (maven), org.apache.syncope.core:syncope-core-provisioning-api (maven), org.apache.syncope.core:syncope-core-provisioning-api (maven). Severity is medium. Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| org.apache.syncope.core:syncope-core-provisioning-apimaven | >=3.0.0-M0,<=3.0.16 | Not reported |
|---|---|---|
| org.apache.syncope.core:syncope-core-provisioning-apimaven | >=4.0.0-M0,<4.0.6 | 4.0.6 |
| org.apache.syncope.core:syncope-core-provisioning-apimaven | >=4.1.0-M0,<4.1.1 | 4.1.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| org.apache.syncope.core:syncope-core-provisioning-apimaven | >=3.0.0-M0,<=3.0.16 | Not reported |
|---|---|---|
| org.apache.syncope.core:syncope-core-provisioning-apimaven | >=4.0.0-M0,<4.0.6 | 4.0.6 |
| org.apache.syncope.core:syncope-core-provisioning-apimaven | >=4.1.0-M0,<4.1.1 | 4.1.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard