Back

CVE-2020-1959

CRITICAL

A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code.

Published: May 4, 2020 Modified: Jun 17, 2026
CWE-917

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
apache syncope * ≥ 2.1.0 < 2.1.6

GitHub Security Advisory GHSA-vjqw-r3ww-wj2w

Expression Language Injection in Apache Syncope

maven org.apache.syncope:syncope-core < 2.1.6 Fixed: 2.1.6

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.82%

Top 9% most likely to be exploited

Threat Score 40.6 / 100

Data Sources

NVD EPSS GitHub