CVE-2024-11209: Apereo CAS 2FA login improper authentication
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11209?
CVE-2024-11209 has been classified as critical.
How does CVE-2024-11209 affect Apereo CAS 6.6.0?
CVE-2024-11209 affects the /login?service endpoint of the 2FA component, leading to improper authentication.
Can CVE-2024-11209 be exploited remotely?
Yes, CVE-2024-11209 can be exploited remotely.
What is the potential impact of exploiting CVE-2024-11209?
Exploiting CVE-2024-11209 can result in unauthorized access due to improper authentication.
How do I patch CVE-2024-11209 in Apereo CAS?
To patch CVE-2024-11209, it is recommended to update Apereo CAS to the latest version that addresses this vulnerability.