CVE-2014-0111
Apache Syncope JEXL Code Injection
EPSS 1.4%
Description
Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."
How to fix CVE-2014-0111
To remediate CVE-2014-0111, upgrade the affected package to a fixed version below.
- Maven/org.apache.syncope:syncope—upgrade to 1.0.9 or later
Is CVE-2014-0111 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.0.0, < 1.0.9