Description
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
Remediation
References
http://syncope.apache.org/security.html#CVE-2018-1322:_Information_disclosure_via_FIQL_and_ORDER_BY_sorting
http://www.securityfocus.com/bid/103507
https://www.exploit-db.com/exploits/45400/
Related Vulnerabilities
CVE-2022-3171 Vulnerability in maven package com.google.protobuf:protobuf-kotlin
CVE-2021-32855 Vulnerability in npm package vditor
CVE-2020-1956 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2019-1003095 Vulnerability in maven package org.jenkins-ci.plugins:perfectomobile
CVE-2016-8629 Vulnerability in maven package org.keycloak:keycloak-services