Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apereo CAS 授权问题漏洞
Vulnerability Description
Apereo CAS是一套基于Web的企业多语言单点登录解决方案。 Apereo CAS 存在安全漏洞,该漏洞源于对使用谷歌身份验证器进行多因素身份验证的密钥处理不当。以下产品及版本受到影响:5.3.x系列 5.3.16之前版本, 6.x系列 6.1.7.2之前版本, 6.2.x系列6.2.4之前版本, 6.3.x系列6.3.0-RC4之前版本。
CVSS Information
N/A
Vulnerability Type
N/A