Vulnerabilities > Apereo > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-14 CVE-2024-11208 Unspecified vulnerability in Apereo Central Authentication Service 6.6.0
A vulnerability was found in Apereo CAS 6.6 and classified as problematic.
network
high complexity
apereo
8.1
2023-12-12 CVE-2018-16153 Insufficiently Protected Credentials vulnerability in Apereo Opencast
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6.
network
low complexity
apereo CWE-522
7.5
2023-06-27 CVE-2023-28857 Insufficiently Protected Credentials vulnerability in Apereo Central Authentication Service
Apereo CAS is an open source multilingual single sign-on solution for the web.
network
low complexity
apereo CWE-522
7.5
2022-11-01 CVE-2022-39369 phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server.
network
low complexity
apereo fedoraproject
8.0
2021-12-14 CVE-2021-43821 Files or Directories Accessible to External Parties vulnerability in Apereo Opencast
Opencast is an Open Source Lecture Capture & Video Management for Education.
network
low complexity
apereo CWE-552
7.7
2020-10-16 CVE-2020-27178 Unspecified vulnerability in Apereo Central Authentication Service
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
network
low complexity
apereo
7.5
2020-01-30 CVE-2020-5230 Injection vulnerability in Apereo Opencast
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used.
network
low complexity
apereo CWE-74
7.5
2020-01-30 CVE-2020-5222 Use of Hard-coded Credentials vulnerability in Apereo Opencast
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key.
network
low complexity
apereo CWE-798
8.8
2020-01-30 CVE-2020-5229 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Apereo Opencast
Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm.
network
low complexity
apereo CWE-327
8.1
2020-01-30 CVE-2020-5228 Missing Authorization vulnerability in Apereo Opencast
Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH.
network
low complexity
apereo CWE-862
7.5