CVE-2018-1322
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
- Affected products
- Apache Syncope
- Apache Syncope
- < 1.2.11, 2.0.8, 1.0.0, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8
- Fix
- Available
- CVSS 3.0
- 4.9 MEDIUM
- EPSS
- 20.1% (97th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2018-03-20
CVE-2018-1322 at NVD
4 known exploits for CVE-2018-1322
Proof-of-concept code and exploit modules indexed by Sploitus