PT-2024-16826 · Apereo · Apereo Cas
Arthur Souza
·
Published
2024-11-14
·
Updated
2024-11-19
·
CVE-2024-11209
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apereo CAS version 6.6
Description
A critical issue affects the 2FA component of Apereo CAS, specifically an unknown part of the file
/login?service. This leads to improper authentication and can be initiated remotely. The exploit has been disclosed publicly, and the vendor was contacted but did not respond.Recommendations
For Apereo CAS version 6.6, update to the latest patch to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the
/login?service file of the 2FA component until a patch is available.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apereo Cas