PT-2024-16824 · Apereo · Apereo Cas
Arthur Souza
·
Published
2024-11-14
·
Updated
2024-11-17
·
CVE-2024-11207
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apereo CAS version 6.6
Description
A vulnerability has been found in Apereo CAS, affecting an unknown functionality of the file /login. The manipulation of the
redirect uri argument leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Recommendations
For Apereo CAS version 6.6, update to the latest release to mitigate risks. Apply the latest patches and review security configurations to ensure the system is secure. As a temporary workaround, consider restricting access to the /login file until a patch is available. Avoid using the
redirect uri argument in the affected file until the issue is resolved.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apereo Cas