CVE-2017-1000071

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
17/07/2017
Last modified:
20/04/2025

Description

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apereo:phpcas:1.3.4:*:*:*:*:*:*:*