Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-39369

Опубликовано: 01 нояб. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8

Описание

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade ...

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps/bionic

ignored

see notes
esm-apps/xenial

ignored

see notes
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

upstream

released

v4.4.1
xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

uses system php-cas
esm-apps/bionic

not-affected

uses system php-cas
esm-apps/focal

not-affected

uses system php-cas
esm-apps/jammy

released

2.8.1+dfsg1-1ubuntu0.1
esm-apps/noble

not-affected

uses system php-cas
esm-apps/xenial

ignored

see notes
focal

not-affected

uses system php-cas
jammy

released

2.8.1+dfsg1-1ubuntu0.1
noble

not-affected

uses system php-cas

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.6.0-1
esm-apps/bionic

ignored

see notes
esm-apps/focal

released

1.3.8-1ubuntu0.20.04.1
esm-apps/jammy

released

1.3.8-1ubuntu0.22.04.1
esm-apps/noble

not-affected

1.6.0-1
esm-apps/xenial

released

1.3.3-2ubuntu1+esm1
focal

released

1.3.8-1ubuntu0.20.04.1
jammy

released

1.3.8-1ubuntu0.22.04.1
kinetic

ignored

end of life, was needed

Показывать по

EPSS

Процентиль: 70%
0.00652
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
больше 2 лет назад

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade tha

CVSS3: 8
debian
больше 2 лет назад

phpCAS is an authentication library that allows PHP applications to ea ...

CVSS3: 8
redos
11 месяцев назад

Уязвимость php-pear-CAS

CVSS3: 8
github
больше 2 лет назад

phpCAS vulnerable to Service Hostname Discovery Exploitation

CVSS3: 8
fstec
больше 2 лет назад

Уязвимость функции phpCAS::setUrl() библиотеки аутентификации phpCAS, позволяющая нарушителю получить доступ к учетной записи пользователя

EPSS

Процентиль: 70%
0.00652
Низкий

8 High

CVSS3