Description
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
Remediation
References
https://apereo.github.io/2020/10/14/gauthvuln/
Related Vulnerabilities
CVE-2023-22946 Vulnerability in maven package org.apache.spark:spark-core_2.13
CVE-2017-9802 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post
CVE-2023-50730 Vulnerability in maven package edu.gemini:gsp-graphql-core_sjs1_2.13
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-jasper
CVE-2021-27578 Vulnerability in maven package org.apache.zeppelin:zeppelin