ZeroHour

CVE-2017-1000071

CVSS 3.0
8.1 high
EPSS
4%p89
Published
()
Modified
Description

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

Vendors
apereo
Products
phpcas
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.