cbcvebase.
CVE-2014-4172
published 2020-01-24

CVE-2014-4172: A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET…

PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.06%
92.6th percentile
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.

Affected

7 ranges
VendorProductVersion rangeFixed in
apereojava_cas_client< 3.3.23.3.2
apereonet_cas_client< 1.0.21.0.2
apereophpcas< 1.3.31.3.3
debiandebian_linux
debianphp-cas< php-cas 1.3.3-1 (bookworm)php-cas 1.3.3-1 (bookworm)
fedoraprojectfedora
jasigphpcas>= 0 < 1.3.31.3.3

Detection & IOCsextracted from sources · hover to see the quote

  • Injection occurs via the 'service' parameter during back-channel CAS ticket validation, targeting AbstractUrlBasedTicketValidator.java
  • Injection also occurs via the 'pgtUrl' parameter during back-channel CAS ticket validation, targeting Cas20ServiceTicketValidator.java
  • The vulnerability is exploitable during the back-channel ticket validation step of the CAS protocol — monitor outbound CAS validation requests for unexpected URL-encoded parameters appended to 'service' or 'pgtUrl' values
  • ·Jasig Java CAS Client versions before 3.3.2 are vulnerable; patch reference commit is ae37092100c8eaec610dab6d83e5e05a8ee58814 on java-cas-client/master
  • ·phpCAS versions before 1.3.3 are vulnerable; Debian fixed in package version 1.3.3-1
  • ·.NET CAS Client versions before 1.0.2 are vulnerable
  • ·Red Hat JBoss Portal 5 (cas-client package) is listed as Affected; JasperReports Server as used in Red Hat Enterprise Virtualization is marked Will Not Fix

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.