Vulnerabilities > Apereo

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2018-16153 Insufficiently Protected Credentials vulnerability in Apereo Opencast
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6.
network
low complexity
apereo CWE-522
7.5
2023-11-09 CVE-2023-4612 Improper Authentication vulnerability in Apereo Central Authentication Service
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7.
network
low complexity
apereo CWE-287
critical
9.8
2023-06-27 CVE-2023-28857 Insufficiently Protected Credentials vulnerability in Apereo Central Authentication Service
Apereo CAS is an open source multilingual single sign-on solution for the web.
network
low complexity
apereo CWE-522
7.5
2022-11-28 CVE-2022-41965 Open Redirect vulnerability in Apereo Opencast
Opencast is a free, open-source platform to support the management of educational audio and video content.
network
low complexity
apereo CWE-601
6.1
2022-11-01 CVE-2022-39369 Improper Validation of Specified Type of Input vulnerability in multiple products
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server.
network
low complexity
apereo fedoraproject CWE-1287
8.0
2022-05-24 CVE-2022-29237 Improper Authentication vulnerability in Apereo Opencast
Opencast is a free and open source solution for automated video capture and distribution at scale.
network
low complexity
apereo CWE-287
5.5
2021-12-14 CVE-2021-43821 Files or Directories Accessible to External Parties vulnerability in Apereo Opencast
Opencast is an Open Source Lecture Capture & Video Management for Education.
network
low complexity
apereo CWE-552
4.0
2021-12-14 CVE-2021-43807 Authentication Bypass by Spoofing vulnerability in Apereo Opencast
Opencast is an Open Source Lecture Capture & Video Management for Education.
network
apereo CWE-290
4.3
2021-12-07 CVE-2021-42567 Cross-site Scripting vulnerability in Apereo Central Authentication Service
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
network
apereo CWE-79
4.3
2021-06-16 CVE-2021-32623 XML Entity Expansion vulnerability in Apereo Opencast
Opencast is a free and open source solution for automated video capture and distribution.
network
low complexity
apereo CWE-776
4.0