7.5
Advisory Published
Updated

CVE-2020-27178

First published: Fri Oct 16 2020(Updated: )

Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Apereo Central Authentication Service>=5.3.0<5.3.16
Apereo Central Authentication Service>=6.0.0<6.1.7.2
Apereo Central Authentication Service>=6.2.0<6.2.4
Apereo Central Authentication Service=6.3.0-rc1
Apereo Central Authentication Service=6.3.0-rc2
Apereo Central Authentication Service=6.3.0-rc3

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-27178?

    CVE-2020-27178 is a vulnerability in the Apereo CAS authentication system that mishandles secret keys with Google Authenticator for multifactor authentication.

  • Which versions of Apereo CAS are affected by CVE-2020-27178?

    Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 are affected by CVE-2020-27178.

  • What is the severity of CVE-2020-27178?

    CVE-2020-27178 has a severity score of 7.5 (high).

  • How does CVE-2020-27178 affect the Apereo CAS authentication system?

    CVE-2020-27178 can lead to mishandling of secret keys in the Apereo CAS authentication system when using Google Authenticator for multifactor authentication.

  • How can I fix CVE-2020-27178 in my Apereo CAS installation?

    To fix CVE-2020-27178, you should upgrade your Apereo CAS installation to version 5.3.16 (for 5.3.x), 6.1.7.2 (for 6.x), 6.2.4 (for 6.2.x), or 6.3.0-RC4 (for 6.3.x).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203