PT-2020-7671 · Jasig · Jasig Java Cas Client
Marvin Addison
·
Published
2014-09-24
·
Updated
2022-05-17
·
CVE-2014-4172
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jasig Java CAS Client versions prior to 3.3.2
.NET CAS Client versions prior to 1.0.2
phpCAS versions prior to 1.3.3
Description
A URL parameter injection issue was found in the CAS protocol, specifically in the back-channel ticket validation step. This allows remote attackers to inject arbitrary web script or HTML via the
service parameter to validation/AbstractUrlBasedTicketValidator.java or the pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.Recommendations
For Jasig Java CAS Client versions prior to 3.3.2, update to version 3.3.2 or later.
For .NET CAS Client versions prior to 1.0.2, update to version 1.0.2 or later.
For phpCAS versions prior to 1.3.3, update to version 1.3.3 or later.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jasig Java Cas Client