Логотип exploitDog
bind:CVE-2022-39369
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39369

Количество 6

Количество 6

ubuntu логотип

CVE-2022-39369

больше 2 лет назад

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade ...

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2022-39369

больше 2 лет назад

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade tha

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2022-39369

больше 2 лет назад

phpCAS is an authentication library that allows PHP applications to ea ...

CVSS3: 8
EPSS: Низкий
redos логотип

ROS-20240808-04

11 месяцев назад

Уязвимость php-pear-CAS

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-8q72-6qq8-xv64

больше 2 лет назад

phpCAS vulnerable to Service Hostname Discovery Exploitation

CVSS3: 8
EPSS: Низкий
fstec логотип

BDU:2024-06190

больше 2 лет назад

Уязвимость функции phpCAS::setUrl() библиотеки аутентификации phpCAS, позволяющая нарушителю получить доступ к учетной записи пользователя

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-39369

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade ...

CVSS3: 8
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-39369

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the CAS server service registry in worst case this may be any other service URL (if the allowed URLs are configured to "^(https)://.*") or may be strictly limited to known and authorized services in the same SSO federation if proper URL service validation is applied. This vulnerability may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while being logged in to the same CAS server. phpCAS 1.6.0 is a major version upgrade tha

CVSS3: 8
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-39369

phpCAS is an authentication library that allows PHP applications to ea ...

CVSS3: 8
1%
Низкий
больше 2 лет назад
redos логотип
ROS-20240808-04

Уязвимость php-pear-CAS

CVSS3: 8
1%
Низкий
11 месяцев назад
github логотип
GHSA-8q72-6qq8-xv64

phpCAS vulnerable to Service Hostname Discovery Exploitation

CVSS3: 8
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-06190

Уязвимость функции phpCAS::setUrl() библиотеки аутентификации phpCAS, позволяющая нарушителю получить доступ к учетной записи пользователя

CVSS3: 8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу