PT-2021-23633 · Apereo · Apereo Cas
Caio Farias
·
Published
2021-12-07
·
Updated
2021-12-10
·
CVE-2021-42567
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apereo CAS versions through 6.4.1
Description
The issue allows for XSS via POST requests sent to the REST API endpoints.
Recommendations
For Apereo CAS versions through 6.4.1, consider restricting access to the REST API endpoints as a temporary workaround until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apereo Cas