3.0.2
18 years ago
2 years ago
Known vulnerabilities in the org.apache.synapse:synapse-extensions package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.synapse:synapse-extensions is an Apache Synapse - Extensions Affected versions of this package are vulnerable to Arbitrary Code Injection due to a lack of controls on the GraalJS and NashornJS Script Mediator engines. An attacker can execute arbitrary code with elevated privileges by submitting crafted scripts to the integration runtime environment. This is only exploitable if the attacker is an authenticated user with administrator or API creator privileges, depending on the product configuration. How to fix Arbitrary Code Injection? Upgrade | [,4.0.0-wso2v255) |