PT-2024-16826 · Apereo · Apereo Cas

Arthur Souza

·

Published

2024-11-14

·

Updated

2024-11-19

·

CVE-2024-11209

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apereo CAS version 6.6
Description A critical issue affects the 2FA component of Apereo CAS, specifically an unknown part of the file /login?service. This leads to improper authentication and can be initiated remotely. The exploit has been disclosed publicly, and the vendor was contacted but did not respond.
Recommendations For Apereo CAS version 6.6, update to the latest patch to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the /login?service file of the 2FA component until a patch is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11209

Affected Products

Apereo Cas