A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 14 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Apereo
Apereo cas
CPEs cpe:2.3:a:apereo:cas:6.6:*:*:*:*:*:*:*
Vendors & Products Apereo
Apereo cas
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Apereo CAS login redirect
Weaknesses CWE-601
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-11-14T12:31:04.225Z

Updated: 2024-11-14T19:32:28.671Z

Reserved: 2024-11-14T06:53:11.652Z

Link: CVE-2024-11207

cve-icon Vulnrichment

Updated: 2024-11-14T19:06:08.489Z

cve-icon NVD

Status : Received

Published: 2024-11-14T13:15:04.603

Modified: 2024-11-14T13:15:04.603

Link: CVE-2024-11207

cve-icon Redhat

No data.