First published: Fri Oct 16 2020(Updated: )
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apereo Central Authentication Service | >=5.3.0<5.3.16 | |
Apereo Central Authentication Service | >=6.0.0<6.1.7.2 | |
Apereo Central Authentication Service | >=6.2.0<6.2.4 | |
Apereo Central Authentication Service | =6.3.0-rc1 | |
Apereo Central Authentication Service | =6.3.0-rc2 | |
Apereo Central Authentication Service | =6.3.0-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27178 is a vulnerability in the Apereo CAS authentication system that mishandles secret keys with Google Authenticator for multifactor authentication.
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 are affected by CVE-2020-27178.
CVE-2020-27178 has a severity score of 7.5 (high).
CVE-2020-27178 can lead to mishandling of secret keys in the Apereo CAS authentication system when using Google Authenticator for multifactor authentication.
To fix CVE-2020-27178, you should upgrade your Apereo CAS installation to version 5.3.16 (for 5.3.x), 6.1.7.2 (for 6.x), 6.2.4 (for 6.2.x), or 6.3.0-RC4 (for 6.3.x).