CVE-2014-4172
published 2020-01-24CVE-2014-4172: A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.06%
92.6th percentile
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apereo | java_cas_client | < 3.3.2 | 3.3.2 |
| apereo | net_cas_client | < 1.0.2 | 1.0.2 |
| apereo | phpcas | < 1.3.3 | 1.3.3 |
| debian | debian_linux | — | — |
| debian | php-cas | < php-cas 1.3.3-1 (bookworm) | php-cas 1.3.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| jasig | phpcas | >= 0 < 1.3.3 | 1.3.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Injection occurs via the 'service' parameter during back-channel CAS ticket validation, targeting AbstractUrlBasedTicketValidator.java ↗
- →Injection also occurs via the 'pgtUrl' parameter during back-channel CAS ticket validation, targeting Cas20ServiceTicketValidator.java ↗
- →The vulnerability is exploitable during the back-channel ticket validation step of the CAS protocol — monitor outbound CAS validation requests for unexpected URL-encoded parameters appended to 'service' or 'pgtUrl' values ↗
- ·Jasig Java CAS Client versions before 3.3.2 are vulnerable; patch reference commit is ae37092100c8eaec610dab6d83e5e05a8ee58814 on java-cas-client/master ↗
- ·phpCAS versions before 1.3.3 are vulnerable; Debian fixed in package version 1.3.3-1 ↗
- ·.NET CAS Client versions before 1.0.2 are vulnerable ↗
- ·Red Hat JBoss Portal 5 (cas-client package) is listed as Affected; JasperReports Server as used in Red Hat Enterprise Virtualization is marked Will Not Fix ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
osv·2022-05-17
CVE-2014-4172 [CRITICAL] Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
GHSA
Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
ghsa·2022-05-17
CVE-2014-4172 [CRITICAL] CWE-74 Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
OSV
CVE-2014-4172: A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3
osv·2020-01-24·CVSS 9.8
CVE-2014-4172 [CRITICAL] CVE-2014-4172: A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
Red Hat
cas-client: Bypass of security constraints via URL parameter injection
vendor_redhat·2014-08-11·CVSS 9.8
CVE-2014-4172 [CRITICAL] cas-client: Bypass of security constraints via URL parameter injection
cas-client: Bypass of security constraints via URL parameter injection
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Will not fix
Package: cas-client (Red Hat JBoss Portal 5) - Affected
Debian
CVE-2014-4172: php-cas - A URL parameter injection vulnerability was found in the back-channel ticket val...
vendor_debian·2014·CVSS 9.8
CVE-2014-4172 [CRITICAL] CVE-2014-4172: php-cas - A URL parameter injection vulnerability was found in the back-channel ticket val...
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
Scope: local
bookworm: resolved (fixed in 1.3.3-1)
bullseye: resolved (fixed in 1.3.3-1)
forky: resolved (fixed in 1.3.3-1)
sid: resolved (fixed in 1.3.3-1)
trixie: resolved (fixed in 1.3.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4172 cas-client: Bypass of security constraints via URL parameter injection
bugzilla·2014-08-19·CVSS 9.8
CVE-2014-4172 [CRITICAL] CVE-2014-4172 cas-client: Bypass of security constraints via URL parameter injection
CVE-2014-4172 cas-client: Bypass of security constraints via URL parameter injection
It was found that URL encoding used in the back-channel ticket validation of the JA-SIG CAS client was improper. A remote attacker could exploit this flaw to bypass security constraints by injecting URL parameters.
Discussion:
External References:
https://www.mail-archive.com/[email protected]/msg17338.html
---
Created cas-client tracking bugs for this issue:
Affects: fedora-all [bug 1131371]
---
Upstream Issue:
https://issues.jasig.org/browse/CASC-228
---
Upstream Commits:
java-cas-client/master
https://github.com/Jasig/java-cas-client/commit/ae37092100c8eaec610dab6d83e5e05a8ee58814
---
Victims Record:
https://github.com/victims/victims-cve-db/blob/master/database/java/2014/4172.yam
Bugzilla
CVE-2014-4172 cas-client: Bypass of security constraints via URL parameter injection [fedora-all]
bugzilla·2014-08-19·CVSS 9.8
CVE-2014-4172 [CRITICAL] CVE-2014-4172 cas-client: Bypass of security constraints via URL parameter injection [fedora-all]
CVE-2014-4172 cas-client: Bypass of security constraints via URL parameter injection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
arXiv
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
arxiv_fulltext·2025-11-28
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Evaluating LLMs for One-Shot Patching of Real and Artificial Vulnerabilities
Aayush Garg
[email protected]
0000-0002-2507-8846
Luxembourg Institute of Science and Technology
Luxembourg
Zanis Ali Khan
[email protected]
0000-0002-3935-2148
Luxembourg Institute of Science and Technology
Luxembourg
Renzo Degiovanni
[email protected]
0000-0003-1611-3969
Luxembourg Institute of Science and Technology
Luxembourg
Qiang Tang
[email protected]
0000-0002-6153-4255
Luxembourg Institute of Science and Technology
Luxembourg
## Abstract
Automated vulnerability patching is crucial for software security, and recent advancements in Large Language Models (LLMs) present promising capabilities for automating this task. However, existing research has primarily assessed LLMs using public
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137182.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759718https://bugzilla.redhat.com/show_bug.cgi?id=1131350https://exchange.xforce.ibmcloud.com/vulnerabilities/95673https://github.com/Jasig/dotnet-cas-client/commit/f0e030014fb7a39e5f38469f43199dc590fd0e8dhttps://github.com/Jasig/java-cas-client/commit/ae37092100c8eaec610dab6d83e5e05a8ee58814https://github.com/Jasig/phpCAS/blob/master/docs/ChangeLoghttps://github.com/Jasig/phpCAS/pull/125https://issues.jasig.org/browse/CASC-228https://www.debian.org/security/2014/dsa-3017.en.htmlhttps://www.mail-archive.com/cas-user%40lists.jasig.org/msg17338.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/137182.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759718https://bugzilla.redhat.com/show_bug.cgi?id=1131350https://exchange.xforce.ibmcloud.com/vulnerabilities/95673https://github.com/Jasig/dotnet-cas-client/commit/f0e030014fb7a39e5f38469f43199dc590fd0e8dhttps://github.com/Jasig/java-cas-client/commit/ae37092100c8eaec610dab6d83e5e05a8ee58814https://github.com/Jasig/phpCAS/blob/master/docs/ChangeLoghttps://github.com/Jasig/phpCAS/pull/125https://issues.jasig.org/browse/CASC-228https://www.debian.org/security/2014/dsa-3017.en.htmlhttps://www.mail-archive.com/cas-user%40lists.jasig.org/msg17338.html
2020-01-24
Published