Back

CVE-2020-1961

CRITICAL

Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.

Published: May 4, 2020 Modified: Jun 17, 2026
CWE-74

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
apache syncope * ≥ 2.0.0 < 2.0.15
apache syncope * ≥ 2.1.0 < 2.1.6

GitHub Security Advisory GHSA-4w4p-xwrr-9crh

Injection in Apache Syncope

maven org.apache.syncope:syncope-core >= 2.0.0, < 2.0.15 Fixed: 2.0.15
maven org.apache.syncope:syncope-core >= 2.1.0, < 2.1.6 Fixed: 2.1.6

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.65%

Top 9% most likely to be exploited

Threat Score 40.6 / 100

Data Sources

NVD EPSS GitHub