CVE-2018-1321
published 2018-03-20CVE-2018-1321: An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x…
PriorityP357high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EXPLOIT
EPSS
18.02%
96.9th percentile
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | — | — |
| apache | syncope | >= 1.2.0 < 1.2.11 | 1.2.11 |
| apache | syncope | >= 2.0.0 < 2.0.8 | 2.0.8 |
| apache_software_foundation | apache_syncope | — | — |
| apache_software_foundation | apache_syncope | — | — |
| assign-deep_project | assign-deep | >= 0 < 0.4.7 | 0.4.7 |
| hapijs | hoek | >= 0 < 4.2.1 | 4.2.1 |
| hapijs | hoek | >= 5.0.0 < 5.0.3 | 5.0.3 |
| just-extend_project | just-extend | >= 0 < 4.0.0 | 4.0.0 |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
ghsa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Dynamic modification of RPyC service due to missing security check
ghsa·2021-02-17·CVSS 7.5
CVE-2019-16328 [HIGH] CWE-1321 Dynamic modification of RPyC service due to missing security check
Dynamic modification of RPyC service due to missing security check
### Impact
Version 4.1.0 of RPyC has a vulnerability that affects custom RPyC services making it susceptible to authenticated remote attacks.
### Patches
Git commits between September 2018 and October 2019 and version 4.1.0 are vulnerable. Use a version of RPyC that is not affected.
### Workarounds
The commit `d818ecc83a92548994db75a0e9c419c7bce680d6` could be used as a patch to add the missing access check.
### References
[CVE-2019-16328](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16328)
[RPyC Security Documentation](https://rpyc.readthedocs.io/en/latest/docs/security.html#security)
### For more information
If you have any questions or comments about this advisory:
* Open an issue using [GitHub](https://g
GHSA
Phar object injection in PHPMailer
ghsa·2020-03-05·CVSS 8.8
CVE-2018-19296 [HIGH] CWE-1321 Phar object injection in PHPMailer
Phar object injection in PHPMailer
PHPMailer versions prior to 6.0.6 and 5.2.27 are vulnerable to an object injection attack by passing phar:// paths into `addAttachment()` and other functions that may receive unfiltered local paths, possibly leading to RCE. See [this article](https://knasmueller.net/5-answers-about-php-phar-exploitation) for more info on this type of vulnerability. Mitigated by blocking the use of paths containing URL-protocol style prefixes such as `phar://`. Reported by Sehun Oh of cyberone.kr.
### Impact
Object injection, possible remote code execution
### Patches
Fixed in 6.0.6 and 5.2.27
### Workarounds
Validate and sanitise user input before using.
### References
https://nvd.nist.gov/vuln/detail/CVE-2018-19296
### For more information
If you have any questions
GHSA
Prototype Pollution in mpath
ghsa·2019-02-07
CVE-2018-16490 [HIGH] CWE-1321 Prototype Pollution in mpath
Prototype Pollution in mpath
Versions of `mpath` before 0.5.1 are vulnerable to prototype pollution. Provided certain input `mpath` can add or modify properties of the `Object` prototype. These properties will be present on all objects.
## Recommendation
Update to version `0.5.1` or later.
GHSA
Prototype Pollution in just-extend
ghsa·2019-02-07
CVE-2018-16489 [CRITICAL] CWE-1321 Prototype Pollution in just-extend
Prototype Pollution in just-extend
Versions of `just-extend` before 4.0.0 are vulnerable to prototype pollution. Provided certain input `just-extend` can add or modify properties of the `Object` prototype. These properties will be present on all objects.
## Recommendation
Update to version `4.0.0` or later.
OSV
High severity vulnerability that affects org.apache.syncope:syncope-core
osv·2018-11-06
CVE-2018-1321 [HIGH] High severity vulnerability that affects org.apache.syncope:syncope-core
High severity vulnerability that affects org.apache.syncope:syncope-core
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11 and 2.0.x before 2.0.8 can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
GHSA
High severity vulnerability that affects org.apache.syncope:syncope-core
ghsa·2018-11-06
CVE-2018-1321 [HIGH] CWE-20 High severity vulnerability that affects org.apache.syncope:syncope-core
High severity vulnerability that affects org.apache.syncope:syncope-core
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11 and 2.0.x before 2.0.8 can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
GHSA
Prototype Pollution in merge
ghsa·2018-11-01
CVE-2018-16469 [HIGH] CWE-1321 Prototype Pollution in merge
Prototype Pollution in merge
Versions of `merge` before 1.2.1 are vulnerable to prototype pollution. The `merge.recursive` function can be tricked into adding or modifying properties of the Object prototype.
## Recommendation
Update to version 1.2.1 or later.
GHSA
Prototype Pollution in async merge-object
ghsa·2018-09-18
CVE-2018-3753 [CRITICAL] CWE-1321 Prototype Pollution in async merge-object
Prototype Pollution in async merge-object
The utilities function in all versions of the merge-object node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
GHSA
Prototype Pollution in assign-deep
ghsa·2018-07-26
CVE-2018-3720 [HIGH] CWE-1321 Prototype Pollution in assign-deep
Prototype Pollution in assign-deep
Versions of `assign-deep` before 0.4.7 are vulnerable to prototype pollution via merging functions.
## Recommendation
Update to version 0.4.7 or later.
GHSA
Prototype Pollution in lodash
ghsa·2018-07-26
CVE-2018-3721 [MEDIUM] CWE-1321 Prototype Pollution in lodash
Prototype Pollution in lodash
Versions of `lodash` before 4.17.5 are vulnerable to prototype pollution.
The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of `Object` via `__proto__` causing the addition or modification of an existing property that will exist on all objects.
## Recommendation
Update to version 4.17.5 or later.
GHSA
Prototype Pollution in hoek
ghsa·2018-04-26
CVE-2018-3728 [HIGH] CWE-1321 Prototype Pollution in hoek
Prototype Pollution in hoek
Versions of `hoek` prior to 4.2.1 and 5.0.3 are vulnerable to prototype pollution.
The `merge` function, and the `applyToDefaults` and `applyToDefaultsWithShallow` functions which leverage `merge` behind the scenes, are vulnerable to a prototype pollution attack when provided an _unvalidated_ payload created from a JSON string containing the `__proto__` property.
This can be demonstrated like so:
```javascript
var Hoek = require('hoek');
var malicious_payload = '{"__proto__":{"oops":"It works !"}}';
var a = {};
console.log("Before : " + a.oops);
Hoek.merge({}, JSON.parse(malicious_payload));
console.log("After : " + a.oops);
```
This type of attack can be used to overwrite existing properties causing a potential denial of service.
## Recommendation
Upda
No detection rules found.
http://syncope.apache.org/security.html#CVE-2018-1321:_Remote_code_execution_by_administrators_with_report_and_template_entitlementshttp://www.securityfocus.com/bid/103508https://www.exploit-db.com/exploits/45400/http://syncope.apache.org/security.html#CVE-2018-1321:_Remote_code_execution_by_administrators_with_report_and_template_entitlementshttp://www.securityfocus.com/bid/103508https://www.exploit-db.com/exploits/45400/
2018-03-20
Published