Metrics
Affected Vendors & Products
Tue, 19 Nov 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apereo central Authentication Service
|
|
CPEs | cpe:2.3:a:apereo:central_authentication_service:6.6.0:-:*:*:*:*:*:* | |
Vendors & Products |
Apereo central Authentication Service
|
Thu, 14 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apereo
Apereo cas Server |
|
CPEs | cpe:2.3:a:apereo:cas_server:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apereo
Apereo cas Server |
|
Metrics |
ssvc
|
Thu, 14 Nov 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Apereo CAS 2FA login improper authentication | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-11-14T13:31:06.281Z
Updated: 2024-11-14T14:29:15.472Z
Reserved: 2024-11-14T06:53:18.271Z
Link: CVE-2024-11209
Updated: 2024-11-14T14:29:09.556Z
Status : Analyzed
Published: 2024-11-14T14:15:18.090
Modified: 2024-11-19T19:14:26.543
Link: CVE-2024-11209
No data.