org.jasig.cas:cas-client-core@3.1-RC1 vulnerabilities

  • latest version

    3.1.10

  • first published

    16 years ago

  • latest version published

    14 years ago

  • licenses detected

  • package manager

Direct Vulnerabilities

Known vulnerabilities in the org.jasig.cas:cas-client-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
URL Parameter Injection

org.jasig.cas:cas-client-core is a Java CAS client.

Affected versions of this package are vulnerable to URL Parameter Injection. It was found that URL encoding used in the back-channel ticket validation of the JA-SIG CAS client was improper. A remote attacker could exploit this flaw to bypass security constraints by injecting URL parameters

How to fix URL Parameter Injection?

Upgrade org.jasig.cas:cas-client-core to version 3.3.2 or higher.

[,3.3.2)