Org.apache.syncope:syncope
3 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Org.apache.syncope:syncope, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Org.apache.syncope:syncope CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 3 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High1
- Medium2
Latest CVEs
The 3 most recently published vulnerabilities affecting Org.apache.syncope:syncope.
- CVE-2020-11977In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, inc...7.2
- CVE-2014-3503Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.5.0
- CVE-2014-0111Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definiti...6.5
Product grouping is registry-driven, with AI assist and human review. How it works