Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000071

Опубликовано: 17 июл. 2017
Источник: debian

Описание

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-casfixed1.3.6-1package
php-casno-dsastretchpackage
php-casno-dsajessiepackage
php-casno-dsawheezypackage

Примечания

  • https://github.com/Jasig/phpCAS/issues/228

  • Fixed by: https://github.com/apereo/phpCAS/commit/c9ba00327fd0ac8faecc62ce150c1986022856cd

  • The vulnerability only exists when the server is affected by

  • another very old vulnerability fixed in 2010.

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 9 лет назад

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

CVSS3: 8.1
nvd
около 9 лет назад

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

CVSS3: 8.1
github
больше 4 лет назад

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.