QID 981830
QID 981830: Java (maven) Security Update for org.apereo.cas:cas-server-support-otp-mfa-core (GHSA-q39c-5vh5-vw2p)
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q39c-5vh5-vw2p for updates pertaining to this vulnerability.
Vendor References
- GHSA-q39c-5vh5-vw2p -
github.com/advisories/GHSA-q39c-5vh5-vw2p
CVEs related to QID 981830
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q39c-5vh5-vw2p | org.apereo.cas:cas-server-support-otp-mfa-core |
|
|
| GHSA-q39c-5vh5-vw2p | org.apereo.cas:cas-server-webapp |
|