CVE-2014-4172
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.06% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- apereo/.net cas client · apereo/java cas client · apereo/phpcas · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137182.htmlThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759718Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1131350Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95673Third Party Advisory, VDB Entry
- https://github.com/Jasig/dotnet-cas-client/commit/f0e030014fb7a39e5f38469f43199dc590fd0e8dPatch, Third Party Advisory
- https://github.com/Jasig/java-cas-client/commit/ae37092100c8eaec610dab6d83e5e05a8ee58814Patch, Third Party Advisory
- https://github.com/Jasig/phpCAS/blob/master/docs/ChangeLogRelease Notes, Third Party Advisory
- https://github.com/Jasig/phpCAS/pull/125Third Party Advisory
- https://issues.jasig.org/browse/CASC-228Third Party Advisory
- https://www.debian.org/security/2014/dsa-3017.en.htmlThird Party Advisory
- https://www.mail-archive.com/cas-user%40lists.jasig.org/msg17338.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137182.htmlThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759718Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1131350Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95673Third Party Advisory, VDB Entry
- https://github.com/Jasig/dotnet-cas-client/commit/f0e030014fb7a39e5f38469f43199dc590fd0e8dPatch, Third Party Advisory
- https://github.com/Jasig/java-cas-client/commit/ae37092100c8eaec610dab6d83e5e05a8ee58814Patch, Third Party Advisory
- https://github.com/Jasig/phpCAS/blob/master/docs/ChangeLogRelease Notes, Third Party Advisory
- https://github.com/Jasig/phpCAS/pull/125Third Party Advisory
- https://issues.jasig.org/browse/CASC-228Third Party Advisory
- https://www.debian.org/security/2014/dsa-3017.en.htmlThird Party Advisory
- https://www.mail-archive.com/cas-user%40lists.jasig.org/msg17338.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.