Description
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
Remediation
References
http://syncope.apache.org/security.html#CVE-2018-1322:_Information_disclosure_via_FIQL_and_ORDER_BY_sorting
http://www.securityfocus.com/bid/103507
https://www.exploit-db.com/exploits/45400/
Related Vulnerabilities
CVE-2020-2181 Vulnerability in maven package org.jenkins-ci.plugins:credentials-binding
CVE-2021-39194 Vulnerability in maven package com.charleskorn.kaml:kaml
CVE-2022-30973 Vulnerability in maven package org.apache.tika:tika
CVE-2021-46037 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-43308 Vulnerability in npm package markdown-link-extractor