CVE-2025-57738 Details
Description
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.
A vulnerability in Apache Syncope allows a malicious administrator to inject Groovy code that can be executed remotely on a running Apache Syncope Core instance. This issue arises from the ability to provide custom implementations of Java interfaces, which can be delivered as Groovy classes. While this feature has been available for some time, it was recently discovered that the injected Groovy code could be executed without proper restrictions. Users are advised to upgrade to Apache Syncope versions 3.0.14 or 4.0.2, which address this vulnerability by enforcing a sandbox environment for Groovy code execution.
Users should upgrade to Apache Syncope version 4.0.2, which is available on the Apache Syncope downloads page. Instructions for upgrading from version 4.0.0 are also provided on the Apache Syncope website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/10/20/1 | CVE | |
| https://lists.apache.org/thread/x7cv6xv7z76y49grdr1hgj1pzw5zbby6 | [email protected] | Mailing ListRelease Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-653 | Improper Isolation or Compartmentalization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache syncope | >= 2.1.0, < 3.0.14 >= 4.0.0, < 4.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Oct 28, 2025 | Initial Analysis | [email protected] |
| Oct 20, 2025 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | New CVE Received | [email protected] |