Impact
Apereo Central Authentication Service (CAS) versions 7.3.0 through 8.0.0‑RC5 use a fixed all‑zero initialization vector for AES‑GCM encryption of web‑flow conversation state. This practice causes keystream reuse across the server lifetime, making the encrypted payloads vulnerable to known‑plaintext analysis. An unauthenticated attacker can visit the public login page, capture multiple web‑flow execution tokens, and de‑crypt the conversation state to reveal sensitive authentication session data. The weakness is classified as CWE‑323 (Improper Handling of Sensitive Information).
Affected Systems
Any deployment of Apereo CAS 7.3.0 up to, but not including, 8.0.0‑RC6 that relies on the default AES‑GCM configuration for session or web‑flow encryption is affected.
Risk and Exploitability
The CVSS score of 9.3 categorises the vulnerability as critical, indicating a high impact on confidentiality with potential for widespread exposure. The EPSS score of < 1% suggests a low current probability of exploitation, yet the attack requires only access to the public login page and no authentication. The vulnerability is not listed in the CISA KEV catalog, but its cryptographic nature and critical CVSS rating mean that exposed systems should treat it as a high‑risk risk from which attackers can gain data compromise.
OpenCVE Enrichment