OSV 1.4.0 · github-reviewed · 修改于 2021-05-05 04:57
发布时间
2021-06-17 01:19
GitHub 审查时间
2021-05-05 04:57
NVD 发布时间
2020-09-16 04:15
源文件
advisories/github-reviewed/2021/06/GHSA-p2rp-cmjq-r7wm/GHSA-p2rp-cmjq-r7wm.json
In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, including but not limited to file read, file write, and code execution.