Vulnerabilities (CVE)

Filtered by vendor Apereo Subscribe
Filtered by product Central Authentication Service
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4612 1 Apereo 1 Central Authentication Service 2023-11-17 N/A 9.8 CRITICAL
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.