PT-2026-91151 · Apache · Apache Syncope
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Syncope versions 3.0.15 through 3.0.16
Apache Syncope versions 4.0.3 through 4.0.7
Apache Syncope versions 4.1.0-M0 through 4.1.2
Description
Sensitive information is inserted into log files. When an AES key of a non-standard length (not 16, 24, or 32 bytes) is configured, the system pads the provided value with random characters and logs the resulting key value.
Recommendations
Upgrade versions 3.0.15 through 3.0.16 to version 4.0.8.
Upgrade versions 4.0.3 through 4.0.7 to version 4.0.8.
Upgrade versions 4.1.0-M0 through 4.1.2 to version 4.1.3.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Syncope