Description

Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.

Remediation

References

Related Vulnerabilities

Severity

Critical

Classification

CWE-74

Tags

Exploit