org.apache.synapse:synapse-extensions@2.1.0 vulnerabilities

  • latest version

    3.0.2

  • first published

    18 years ago

  • latest version published

    2 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.synapse:synapse-extensions package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Arbitrary Code Injection

    org.apache.synapse:synapse-extensions is an Apache Synapse - Extensions

    Affected versions of this package are vulnerable to Arbitrary Code Injection due to a lack of controls on the GraalJS and NashornJS Script Mediator engines. An attacker can execute arbitrary code with elevated privileges by submitting crafted scripts to the integration runtime environment. This is only exploitable if the attacker is an authenticated user with administrator or API creator privileges, depending on the product configuration.

    How to fix Arbitrary Code Injection?

    Upgrade org.apache.synapse:synapse-extensions to version 4.0.0-wso2v255 or higher.

    [,4.0.0-wso2v255)