Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance.
Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-825g-mm5v-ggq4 | Apache Syncope allows malicious administrators to inject Groovy code |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:* |
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache syncope |
|
| Vendors & Products |
Apache
Apache syncope |
Mon, 20 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox. | |
| Title | Apache Syncope: Remote Code Execution by delegated administrators | |
| Weaknesses | CWE-653 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:13:18.181Z
Reserved: 2025-08-19T06:32:04.510Z
Link: CVE-2025-57738
Updated: 2025-11-04T21:13:18.181Z
Status : Modified
Published: 2025-10-20T15:15:33.553
Modified: 2025-11-04T22:16:31.757
Link: CVE-2025-57738
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:39:48Z
Github GHSA