CRITICAL🇵🇱 Wersja polska

CVE-2024-4399

CVSS 9.1v3.1pub. 2024-05-23upd. 2025-06-30

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

🤖 AI Analysis
How it works

The application does not validate the value of the passed parameter before executing a network request to the specified resource. An attacker, without needing any privileges, can provide a crafted parameter value pointing to internal infrastructure resources or external servers. The server then executes the request on behalf of the attacker, which can lead to information disclosure or interaction with resources not directly accessible from outside.

Impact

An attacker can gain access to internal network resources (e.g., services on the LAN, cloud environment metadata) and cause disclosure of sensitive information. The vulnerability can also be exploited to scan internal infrastructure or bypass perimeter security measures.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Additionally, it is recommended to implement firewall rules limiting the server's ability to initiate outgoing connections to internal network segments, and to verify and filter input parameters on the application side.

Who is affected

Apereo Central Authentication Service — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apereo Central Authentication Service

    APP
    Apereo
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2023-4612CRITICAL9.8PL ✓same product

Apereo CAS — pominięcie uwierzytelnienia wieloskładnikowego (MFA bypass)

CVE-2020-27178HIGH7.5same product

Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles ...

CVE-2019-10754HIGH8.1same product

Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStrin...

CVE-2015-1169HIGH7.5same product

Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP inject...

CVE-2025-3985MEDIUM5.1same product

A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the functio...