Severity: moderate
Affected versions:
- Apache Syncope
(org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui) 4.0.4
through 4.0.7
- Apache Syncope
(org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui) 4.1.0-M0
through 4.1.2
Description:
Improper neutralization of input during web page generation ('cross-site
scripting') vulnerability in Apache Syncope.
The notification message, as optionally shown by Console's and Enduser's login
pages can be instructed to display HTML tags with unsafe JS inline, via
malicious HTTP link generation.
This issue affects Apache Syncope: from 4.0.4 through 4.0.7, from 4.1.0-M0
through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Credit:
Alon Galili (finder)
References:
https://syncope.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-78318