Security Advisory

CVE-2018-1322

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-20 17:00:00
Last updated 2024-09-16 17:03:34
Assigner apache
CVSS score not scored
State PUBLISHED

Description

An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.