CVEs (13)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apereo 1Central Authentication Service Jun 17, 2026 Apr 27, 2025 5.3 MEDIUM· v4 7.5 HIGH· v3 4.0 MEDIUM· v2 A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\a...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 Apr 27, 2025 5.1 MEDIUM· v4 4.9 MEDIUM· v3 3.3 LOW· v2 A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 Apr 27, 2025 2.3 LOW· v4 7.5 HIGH· v3 4.6 MEDIUM· v2 A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mg...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 Nov 14, 2024 5.3 MEDIUM· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is poss...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 Nov 14, 2024 6.3 MEDIUM· v4 8.1 HIGH· v3 2.6 LOW· v2 A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 Nov 14, 2024 5.3 MEDIUM· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open r...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 May 23, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack |
1Apereo 1Central Authentication Service Jun 17, 2026 Nov 9, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown wheth...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 Jun 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or...Show more |
1Apereo 1Central Authentication Service Jun 17, 2026 Dec 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. |
1Apereo 1Central Authentication Service Jun 17, 2026 Oct 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication. |
1Apereo 1Central Authentication Service Jun 17, 2026 Sep 23, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not...Show more |
1Apereo 1Central Authentication Service May 6, 2026 Feb 10, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP au...Show more |