Логотип exploitDog
bind:CVE-2014-3527
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-3527

Количество 5

Количество 5

ubuntu логотип

CVE-2014-3527

больше 8 лет назад

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2014-3527

больше 11 лет назад

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2014-3527

больше 8 лет назад

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2014-3527

больше 8 лет назад

When using the CAS Proxy ticket authentication from Spring Security 3. ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wmv4-5w76-vp9g

больше 5 лет назад

Authorization Bypass in Spring Security

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-3527

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2014-3527

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-3527

When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2014-3527

When using the CAS Proxy ticket authentication from Spring Security 3. ...

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
github логотип
GHSA-wmv4-5w76-vp9g

Authorization Bypass in Spring Security

CVSS3: 9.8
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу