VYPR

Central Authentication Service

by Apereo

CVEs (13)

  • CVE-2023-4612CriNov 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date…

  • CVE-2024-4399CriMay 23, 2024
    risk 0.59cvss 9.1epss 0.02

    The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

  • CVE-2020-27178HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.

  • CVE-2019-10754HigSep 23, 2019
    risk 0.46cvss 8.1epss 0.02

    Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong.

  • CVE-2024-11209MedNov 14, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-3984MedApr 27, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java…

  • CVE-2021-42567MedDec 7, 2021
    risk 0.33cvss 6.1epss 0.08

    Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.

  • CVE-2025-3986MedApr 27, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerContro…

  • CVE-2024-11207MedNov 14, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit…

  • CVE-2024-11208LowNov 14, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather…

  • CVE-2023-28857MedJun 27, 2023
    risk 0.19cvss 4.0epss 0.01

    Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When…

  • CVE-2025-3985LowApr 27, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionControl…

  • CVE-2015-1169Feb 10, 2015
    risk 0.00cvss epss 0.03

    Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.