First published: Tue Feb 10 2015(Updated: )
Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apereo Central Authentication Service | <=3.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.