CVE-2014-2296

XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated users to bypass authentication via crafted XML data.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apereo:cas_server:*:*:*:*:*:*:*:*
cpe:2.3:a:apereo:cas_server:*:*:*:*:*:*:*:*

Information

Published : 2018-07-20 10:29

Updated : 2018-09-19 06:31


NVD link : CVE-2014-2296

Mitre link : CVE-2014-2296


JSON object : View

CWE
CWE-611

Improper Restriction of XML External Entity Reference

Advertisement

dedicated server usa

Products Affected

apereo

  • cas_server