
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Apache Syncope, the widely deployed open-source identity management platform, has patched a batch of critical vulnerabilities that could let low-privilege users escalate to administrator status and execute arbitrary code on the server. The Apache Software Foundation disclosed six new CVEs affecting versions 3.0.x, 4.0.x, and 4.1.x, with fixes rolled out in versions 4.1.2 and 4.0.7. […]
The post Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code appeared first on Cyber Security News.