Syracom's vulnerability footprint centers on its Secure Login authentication product, with observed weaknesses spanning rate-limiting controls, privilege assignment logic, and redirect validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syracom over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22958MEDIUM The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter. | Jan 11, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-48942MEDIUM The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofacto | Oct 10, 2024 | 5.9 | 16 | NO | NO |
CVE-2024-48941MEDIUM The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Conf | Oct 10, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syracom.
Media articles that mention a CVE ID that affects a product developed by Syracom — matched by CVE ID, not by vendor name.