Impact
A cryptographic flaw in Apereo CAS 7.3.0 and earlier versions uses a fixed all‑zero initialization vector for AES‑GCM encryption of web‑flow conversation state, which causes keystream reuse across the server lifetime. An unauthenticated attacker can collect multiple web‑flow execution tokens from the public login page and apply known‑plaintext analysis to recover the plaintext conversation state, exposing sensitive authentication session data. This weakness is classified as CWE‑323 (Improper Handling of Sensitive Information).
Affected Systems
Any deployment of Apereo CAS from version 7.3.0 through 8.0.0‑RC5 that relies on the default AES‑GCM configuration for session or web‑flow encryption is affected.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, classifying it as critical and indicating a high impact on confidentiality. The EPSS score of <1% suggests a low current probability of exploitation, but because the attack requires only unauthenticated access to the public login page and no additional credentials, the exploitability is trivially low. The vulnerability is not listed in the CISA KEV catalog, yet its cryptographic nature and critical CVSS rating demand urgent remediation.
OpenCVE Enrichment