Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000071

Опубликовано: 17 июл. 2017
Источник: debian
EPSS Низкий

Описание

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-casfixed1.3.6-1package
php-casno-dsastretchpackage
php-casno-dsajessiepackage
php-casno-dsawheezypackage

Примечания

  • https://github.com/Jasig/phpCAS/issues/228

  • Fixed by: https://github.com/apereo/phpCAS/commit/c9ba00327fd0ac8faecc62ce150c1986022856cd

  • The vulnerability only exists when the server is affected by

  • another very old vulnerability fixed in 2010.

EPSS

Процентиль: 48%
0.00249
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

CVSS3: 8.1
nvd
больше 8 лет назад

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

CVSS3: 8.1
github
больше 3 лет назад

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

EPSS

Процентиль: 48%
0.00249
Низкий