-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.syncope:syncope | maven | >= 1.0.0, < 1.0.9 | 1.0.9 |
| org.apache.syncope:syncope | maven | >= 1.1.0, < 1.1.7 | 1.1.7 |
The analysis focuses on components explicitly mentioned in vulnerability descriptions: derived schemas, templates, and resource mappings. While exact patch details are unavailable, the Syncope security advisory confirms JEXL expression handling in these components was vulnerable. Functions were identified by combining: 1) Component names from vulnerability description 2) Syncope's package structure 3) JEXL integration patterns 4) Common workflow processing methods. Confidence is medium due to inferred code structure rather than direct patch analysis, but strongly aligned with documented attack vectors and Apache Syncope architecture.