Vulnerabilities > Apereo > Central Authentication Service > 6.3.7
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-09 | CVE-2023-4612 | Improper Authentication vulnerability in Apereo Central Authentication Service Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. | 9.8 |
2021-12-07 | CVE-2021-42567 | Cross-site Scripting vulnerability in Apereo Central Authentication Service Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. | 6.1 |