CVE-2018-1322: Information disclosure via FIQL and ORDER BY sorting
The Apache Software Foundation
* Releases prior to 1.2.11
* Releases prior to 2.0.8
The unsupported Releases 1.0.x, 1.1.x may be also affected.
An administrator with user search entitlements can recover sensitive
security values using the fiql and orderby parameters.
Syncope 1.2.x users upgrade to 1.2.11.
Syncope 2.0.x users upgrade to 2.0.8.
Do not assign user search entitlements to any administrator.
This issue was discovered by Che-Chun Kuo.