Severity: moderate 

Affected versions:

- Apache Syncope (org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic) 
3.0.0-M0 through 3.0.16
- Apache Syncope (org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic) 
4.0.0-M0 through 4.0.7
- Apache Syncope (org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic) 
4.1.0-M0 through 4.1.2

Description:

Insertion of sensitive information into sent data vulnerability in Apache 
Syncope.



Any authenticated user can query for the list of available OIDC providers 
configured for SSO with Console and Enduser. The returned payload contains all 
configuration settings, including client secrets, regardless of the 
entitlements owned by the caller.



This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 
through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Credit:

Moritz Theile (finder)

References:

https://syncope.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-78336

Reply via email to