First published: Mon Nov 18 2019(Updated: )
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blackboard Blackboard Learn | =2018-07-02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13257 is a vulnerability found in the bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02.
The severity of CVE-2018-13257 is medium with a CVSS score of 6.1.
Blackboard Learn 2018-07-02 is affected by CVE-2018-13257 due to the vulnerability in the bb-auth-provider-cas authentication module.
CVE-2018-13257 allows for HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
To fix CVE-2018-13257, it is recommended to update to a patched version of Blackboard Learn 2018-07-02 or apply any available security patches provided by the vendor.