CVE-2017-1000071Improper Authentication in Phpcas

Severity
8.1HIGHNVD
EPSS
0.2%
top 51.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17
Latest updateMay 13

Description

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages2 packages

NVDapereo/phpcas1.3.4
debiandebian/php-cas< php-cas 1.3.6-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-fwrj-8jg7-7jr6: Jasig phpCAS version 12022-05-13
OSV
CVE-2017-1000071: Jasig phpCAS version 12017-07-17

📋Vendor Advisories

1
Debian
CVE-2017-1000071: php-cas - Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the vali...2017
CVE-2017-1000071 — Improper Authentication in Phpcas | cvebase