← Back

CVE-2014-2296

nvd nist
Published: Jul 20, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated users to bypass authentication via crafted XML data.

Affected (2)

Products: Apereo: Cas Server
1 product
Cas Server
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apereo
Before 3.4.12.1
From 3.5 to 3.5.2.1

Timeline

No history available yet.