CVE-2014-2296: XEE
XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated users to bypass authentication via crafted XML data.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this XXE vulnerability?
The vulnerability ID for this XML external entity (XXE) vulnerability is CVE-2014-2296.
What is the severity of CVE-2014-2296?
The severity of CVE-2014-2296 is high, with a severity value of 8.8.
Which software is affected by CVE-2014-2296?
The Apereo Cas Server versions 3.4.12.1 and 3.5.x before 3.5.2.1 are affected by CVE-2014-2296.
How does CVE-2014-2296 allow bypassing authentication?
CVE-2014-2296 allows remote unauthenticated users to bypass authentication by exploiting a XML external entity vulnerability in Jasig CAS server when Google Accounts Integration is enabled.
Where can I find more information about CVE-2014-2296?
More information about CVE-2014-2296 can be found at the following references: [http://jasig.275507.n4.nabble.com/CAS-3-5-2-1-and-3-4-12-1-Security-Releases-td4662444.html](http://jasig.275507.n4.nabble.com/CAS-3-5-2-1-and-3-4-12-1-Security-Releases-td4662444.html) and [https://vigilance.fr/vulnerability/Jasig-CAS-Server-bypassing-authentication-via-Google-Accounts-Integration-14512](https://vigilance.fr/vulnerability/Jasig-CAS-Server-bypassing-authentication-via-Google-Accounts-Integration-14512).