CVE-2017-1000071: High severity apereo phpcas vulnerability
Published Jul 13, 2017
·Updated
Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.
Affected Software
1 affected component
Apereo Phpcas=1.3.4
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000071?
CVE-2017-1000071 is classified as a high severity vulnerability due to the potential for authentication bypass.
2
How do I fix CVE-2017-1000071?
To fix CVE-2017-1000071, upgrade to a newer version of phpCAS that patches the authentication bypass issue.
3
What specific versions of phpCAS are affected by CVE-2017-1000071?
CVE-2017-1000071 affects phpCAS version 1.3.4 when configured to authenticate against old CAS servers.
4
Can CVE-2017-1000071 allow unauthorized access?
Yes, CVE-2017-1000071 can allow attackers to bypass authentication and gain unauthorized access to protected resources.
5
Is there a temporary workaround for CVE-2017-1000071?
There are no documented temporary workarounds for CVE-2017-1000071; upgrading to a secure version is recommended.