CVE-2021-42567: XSS
Published Dec 7, 2021
·Updated
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Affected Software
2 affected components
Apereo Central Authentication Service>=6.3.0<6.3.7.1
Apereo Central Authentication Service>=6.4.0<6.4.2
Remediation
Patch Available
Event History
Dec 7, 2021
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-42567?
CVE-2021-42567 is a vulnerability in Apereo CAS that allows XSS via POST requests sent to the REST API endpoints.
2
What is the severity of CVE-2021-42567?
CVE-2021-42567 has a severity rating of medium.
3
Which versions of Apereo CAS are affected by CVE-2021-42567?
Apereo CAS versions 6.3.0 to 6.3.7.1 and versions 6.4.0 to 6.4.2 are affected by CVE-2021-42567.
4
How can an attacker exploit CVE-2021-42567?
An attacker can exploit CVE-2021-42567 by sending malicious POST requests to the REST API endpoints.
5
Is there a fix available for CVE-2021-42567?
Yes, the fix for CVE-2021-42567 is available in the latest release of Apereo CAS. It is recommended to update to the latest version to mitigate this vulnerability.