PT-2024-16824 · Apereo · Apereo Cas

Arthur Souza

·

Published

2024-11-14

·

Updated

2024-11-17

·

CVE-2024-11207

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apereo CAS version 6.6
Description A vulnerability has been found in Apereo CAS, affecting an unknown functionality of the file /login. The manipulation of the redirect uri argument leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations For Apereo CAS version 6.6, update to the latest release to mitigate risks. Apply the latest patches and review security configurations to ensure the system is secure. As a temporary workaround, consider restricting access to the /login file until a patch is available. Avoid using the redirect uri argument in the affected file until the issue is resolved.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11207

Affected Products

Apereo Cas