CVE-2020-27178
16.10.2020, 16:15
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.Enginsight
Vendor | Product | Version |
---|---|---|
apereo | central_authentication_service | 5.3.0 ≤ 𝑥 < 5.3.16 |
apereo | central_authentication_service | 6.0.0 ≤ 𝑥 < 6.1.7.2 |
apereo | central_authentication_service | 6.2.0 ≤ 𝑥 < 6.2.4 |
apereo | central_authentication_service | 6.3.0:rc1 |
apereo | central_authentication_service | 6.3.0:rc2 |
apereo | central_authentication_service | 6.3.0:rc3 |
𝑥
= Vulnerable software versions