The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of CAS Client Java

computer vulnerability announce CVE-2014-4172

Jasig CAS: access control bypass

Synthesis of the vulnerability

An attacker can use several vulnerabilities of URL of Jasig CAS.
Impacted products: CAS Client Java, Debian, Fedora.
Severity: 3/4.
Consequences: privileged access/rights, client access/rights, data reading, data creation/edition.
Provenance: intranet client.
Number of vulnerabilities in this bulletin: 2.
Creation date: 12/08/2014.
Identifiers: CVE-2014-4172, DSA-3017-1, FEDORA-2014-9662, RHSA-2015:1009, VIGILANCE-VUL-15147.

Description of the vulnerability

Several vulnerabilities were announced in Jasig CAS.

A client attacker who have an authorization for a service can use it to access another service, in order to escalate his privileges. [severity:3/4]

A server attacker A can use a client authorization for A to access another server B with the access rights of this client. [severity:2/4]
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about CAS Client Java: