Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxgj-cfm7-w8hw

Опубликовано: 09 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.

Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.

EPSS

Процентиль: 13%
0.00044
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-302

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.

EPSS

Процентиль: 13%
0.00044
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-302