Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Joachim Fritschi

#21574de 53,640
11.1CVSS total
Vulnerabilidades · 2
Média
2
PT-2019-6732
5.3
2019-12-05
Apereo · Phpcas · CVE-2012-1104
**Name of the Vulnerable Software and Affected Versions** phpCAS version 1.2.2 **Description** A Security Bypass issue exists due to the way proxying of services are managed. **Recommendations** For phpCAS version 1.2.2, at the moment, there is no information about a newer version that contains a fix for this issue.
PT-2014-2344
5.8
2014-06-06
Apereo · Phpcas · CVE-2012-5583
**Name of the Vulnerable Software and Affected Versions** phpCAS versions prior to 1.3.2 **Description** The issue arises from the failure to verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. This allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. **Recommendations** For versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider implementing additional certificate validation checks to ensure the server hostname matches the domain name in the certificate.