CVE-2018-1322: Apache Syncope
Medium severity, CVSS 4.9. EPSS: 19.9% chance of exploitation in the next 30 days.
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
Affected products
- Apache Syncope: from 1.2.0, before 1.2.11 (fixed in 1.2.11); from 2.0.0, before 2.0.8 (fixed in 2.0.8); version 1.0.0 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …
Published 2018-03-20. Last modified 2026-06-17.