Apereo
Apereo Central Authentication Service: vulnerabilidades y CVE
Apereo Central Authentication Service tiene 15 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-12266 | Baja (2.1) | 0.33% | — | 27 oct 2025 | A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the function _empty of the file /index.php/auth/widget. Performing manipulation… |
| CVE-2025-11284 | Media (5.5) | 0.43% | — | 5 oct 2025 | A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP… |
| CVE-2025-3986 | Media (5.3) | 0.64% | — | 27 abr 2025 | A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file… |
| CVE-2025-3985 | Media (5.1) | 0.62% | — | 27 abr 2025 | A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file… |
| CVE-2025-3984 | Baja (2.3) | 0.48% | — | 27 abr 2025 | A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file… |
| CVE-2024-11209 | Media (5.3) | 0.62% | — | 14 nov 2024 | A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is… |
| CVE-2024-11208 | Media (6.3) | 0.75% | — | 14 nov 2024 | A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be… |
| CVE-2024-11207 | Media (5.3) | 0.36% | — | 14 nov 2024 | A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open… |
| CVE-2024-4399 | Crítica (9.1) | 1.8% | — | 23 may 2024 | The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack |
| CVE-2023-4612 | Crítica (9.8) | 0.94% | — | 9 nov 2023 | Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown… |
| CVE-2023-28857 | Alta (7.5) | 0.50% | — | 27 jun 2023 | Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake… |
| CVE-2021-42567 | Media (6.1) | 8.2% | — | 7 dic 2021 | Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. |
| CVE-2020-27178 | Alta (7.5) | 1.2% | — | 16 oct 2020 | Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication. |
| CVE-2019-10754 | Alta (8.1) | 1.8% | — | 23 sept 2019 | Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not… |
| CVE-2015-1169 | Alta (7.5) | 2.8% | — | 10 feb 2015 | Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP… |