Public PoC and Technical Details Disclosed for Apache Syncope RCE
ID: 9063cdfb-f13c-511e-b844-c50222191296
STIX ID: report--9063cdfb-f13c-511e-b844-c50222191296
Feed Name: securityonline.info
Threat Score
SecureLayer7 disclosed CVE-2025-57738: a high-severity RCE in Apache Syncope where uploaded Groovy implementations are compiled with an unsandboxed GroovyClassLoader, allowing static initializers to execute arbitrary JVM code (including Runtime.exec and ProcessBuilder). A public PoC demonstrates root-level execution in a Docker deployment; the vendor mitigation is to upgrade to Syncope 3.0.14 or 4.0.2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
