Back to search
CVE-2015-1169
Published: Feb 10, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150121 CVE-2015-1169 - CAS Server 3.5.2 allows remote attackers to bypass LDAP authentication via crafted wildcards.
mailing-list
x_refsource_FULLDISC
https://github.com/Jasig/cas/pull/411
x_refsource_CONFIRM
https://issues.jasig.org/browse/CAS-1429
x_refsource_CONFIRM
https://github.com/Jasig/cas/commit/7de61b4c6244af9ff8e75a2c92a570f3b075309c
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now