Apereo central authentication service是Apereo组织开源的一款单点登录认证服务系统。 Apereo Central Authentication Service 4.1.0版本和Jasig CAS Client 3.6.4版本存在加密问题漏洞,该漏洞源于接受任何CA信任的证书,可能导致具有中间人攻击位置的攻击者拦截CAS交换、捕获TGT并获取服务票据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apereo | Jasig CAS Client | 3.6.4 |
affected |
| Apereo | Java Apereo CAS Client | 4.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apereo | Java Apereo CAS Client | 4.1.0 | - |
|
| Apereo | Jasig CAS Client | 3.6.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet