Skip to main content

Vendor/product archive

apereo / central_authentication_service CVEs

Beta · best-effort

13 CVEs tagged to apereo / central_authentication_service2 Critical, 3 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2025-3984

Published Apr 27, 2025

A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webap…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-11209

Published Nov 14, 2024

A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation lea…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11208

Published Nov 14, 2024

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11207

Published Nov 14, 2024

A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28857

Published Jun 27, 2023

Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certific…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-27178

Published Oct 16, 2020

Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10754

Published Sep 23, 2019

Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1169

Published Feb 10, 2015

Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1