CVE-2024-4399: CAS <= 1.0.0 - Unauthenticated SSRF
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4399?
CVE-2024-4399 is classified as a critical vulnerability due to the potential for SSRF attacks by unauthenticated users.
How do I fix CVE-2024-4399?
To fix CVE-2024-4399, update the Apereo Central Authentication Service to the latest version or apply a security patch that addresses the SSRF issue.
Which software is affected by CVE-2024-4399?
CVE-2024-4399 affects the Apereo Central Authentication Service, specifically versions up to 1.0.0 and also impacts installations integrated with Wordpress.
Can CVE-2024-4399 lead to data exposure?
Yes, CVE-2024-4399 can lead to unauthorized data exposure as it may allow attackers to access internal services through SSRF exploitation.
Is CVE-2024-4399 exploitable remotely?
Yes, CVE-2024-4399 is exploitable remotely by unauthenticated users, making it a significant security concern.