Описание
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade ...
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support |
| devel | DNE | |
| esm-apps-legacy/xenial | ignored | see notes |
| esm-apps/bionic | ignored | see notes |
| esm-apps/xenial | ignored | end of ESM support, was ignored [see notes] |
| esm-infra/focal | DNE | |
| focal | DNE | |
| jammy | DNE | |
| noble | DNE | |
| upstream | released | v4.4.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support |
| devel | not-affected | uses system php-cas |
| esm-apps-legacy/xenial | ignored | see notes |
| esm-apps/bionic | not-affected | uses system php-cas |
| esm-apps/focal | not-affected | uses system php-cas |
| esm-apps/jammy | released | 2.8.1+dfsg1-1ubuntu0.1 |
| esm-apps/noble | not-affected | uses system php-cas |
| esm-apps/xenial | ignored | end of ESM support, was ignored [see notes] |
| focal | not-affected | uses system php-cas |
| jammy | released | 2.8.1+dfsg1-1ubuntu0.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| devel | not-affected | 1.6.0-1 |
| esm-apps-legacy/xenial | released | 1.3.3-2ubuntu1+esm1 |
| esm-apps/bionic | ignored | see notes |
| esm-apps/focal | released | 1.3.8-1ubuntu0.20.04.1 |
| esm-apps/jammy | released | 1.3.8-1ubuntu0.22.04.1 |
| esm-apps/noble | not-affected | 1.6.0-1 |
| esm-apps/xenial | released | 1.3.3-2ubuntu1+esm1 |
| focal | released | 1.3.8-1ubuntu0.20.04.1 |
| jammy | released | 1.3.8-1ubuntu0.22.04.1 |
Показывать по
EPSS
8 High
CVSS3
Связанные уязвимости
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade tha
phpCAS is an authentication library that allows PHP applications to ea ...
phpCAS vulnerable to Service Hostname Discovery Exploitation
Уязвимость функции phpCAS::setUrl() библиотеки аутентификации phpCAS, позволяющая нарушителю получить доступ к учетной записи пользователя
EPSS
8 High
CVSS3