Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated users to bypass authentication via crafted XML data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Jasig CAS Server 安全漏洞
Vulnerability Description
Jasig CAS server是一套单点登录系统。 Jasig CAS server 3.4.12.1之前版本和3.5.2.1之前的3.5.x版本中的java/org/jasig/cas/util/SamlUtils.java文件存在XML外部实体注入漏洞。当Google Accounts Integration被启用时,远程攻击者可借助特制的XML数据利用该漏洞绕过身份验证。
CVSS Information
N/A
Vulnerability Type
N/A