Critical severity9.8NVD Advisory· Published Jan 24, 2020· Updated Jun 17, 2026
CVE-2014-4172
CVE-2014-4172
Description
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DotNetCasClientNuGet | < 1.0.2 | 1.0.2 |
org.jasig.cas:cas-clientMaven | < 3.3.2 | 3.3.2 |
jasig/phpcasPackagist | < 1.3.3 | 1.3.3 |
Affected products
9- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
- Jasig/Java CAS Client, .NET CAS Client, and phpCASdescription
- ghsa-coords3 versions
< 1.3.3+ 2 more
- (no CPE)range: < 1.3.3
- (no CPE)range: < 3.3.2
- (no CPE)range: < 1.0.2
Patches
Vulnerability mechanics
References
15- github.com/Jasig/dotnet-cas-client/commit/f0e030014fb7a39e5f38469f43199dc590fd0e8dnvdPatchThird Party AdvisoryWEB
- github.com/Jasig/java-cas-client/commit/ae37092100c8eaec610dab6d83e5e05a8ee58814nvdPatchThird Party AdvisoryWEB
- lists.fedoraproject.org/pipermail/package-announce/2014-August/137182.htmlnvdThird Party AdvisoryWEB
- bugs.debian.org/cgi-bin/bugreport.cginvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/95673nvdThird Party AdvisoryVDB EntryWEB
- github.com/Jasig/phpCAS/blob/master/docs/ChangeLognvdRelease NotesThird Party AdvisoryWEB
- github.com/Jasig/phpCAS/pull/125nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-9fc5-q25c-r2wrghsaADVISORY
- issues.jasig.org/browse/CASC-228nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2014-4172ghsaADVISORY
- www.debian.org/security/2014/dsa-3017.en.htmlnvdThird Party AdvisoryWEB
- github.com/apereo/java-cas-client/commit/266eba7c2d870d70caba6f41576d19f2fcc869b1ghsaWEB
- www.mail-archive.com/[email protected]/msg17338.htmlghsaWEB
- www.mail-archive.com/cas-user%40lists.jasig.org/msg17338.htmlnvd
News mentions
0No linked articles in our index yet.