CVE-2020-27178: High severity apereo cas vulnerability
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27178?
CVE-2020-27178 is a vulnerability in the Apereo CAS authentication system that mishandles secret keys with Google Authenticator for multifactor authentication.
Which versions of Apereo CAS are affected by CVE-2020-27178?
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 are affected by CVE-2020-27178.
What is the severity of CVE-2020-27178?
CVE-2020-27178 has a severity score of 7.5 (high).
How does CVE-2020-27178 affect the Apereo CAS authentication system?
CVE-2020-27178 can lead to mishandling of secret keys in the Apereo CAS authentication system when using Google Authenticator for multifactor authentication.
How can I fix CVE-2020-27178 in my Apereo CAS installation?
To fix CVE-2020-27178, you should upgrade your Apereo CAS installation to version 5.3.16 (for 5.3.x), 6.1.7.2 (for 6.x), 6.2.4 (for 6.2.x), or 6.3.0-RC4 (for 6.3.x).