GHSL-2023-009: Credentials leaks for LDAP authentication in Apereo CAS - CVE-2023-28857
When CAS is configured to use X509 certificate authentication with LDAP directory, an unauthenticated user can leak the credentials for LDAP authentication. This is possible by sending a specially crafted X509 client certificate that contains a “CRL Distribution Points” extension with URLs pointing to a malicious resource.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2023-009?
The severity of GHSL-2023-009 is rated at 65.
How do I fix GHSL-2023-009?
To fix GHSL-2023-009, ensure that the CAS configuration does not allow unauthenticated users to exploit X509 certificate authentication with LDAP.
What specifically causes the GHSL-2023-009 vulnerability?
GHSL-2023-009 is caused by the improper handling of a specially crafted X509 client certificate that leaks LDAP authentication credentials.
What systems are affected by GHSL-2023-009?
The GHSL-2023-009 vulnerability affects Apereo CAS when configured with X509 certificate authentication and LDAP directory.
Can an authenticated user exploit GHSL-2023-009?
No, GHSL-2023-009 can be exploited by unauthenticated users.