CVE Published: 09/11/2023 |
CVE Updated: 10/10/2024 |
CVE Year: 2023 Source: CERT-PL |
Vendor: Apereo Foundation |
Product: CAS Status : PUBLISHED
CVE-2023-4612 Description
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.