CVE-2024-11209

CVSS 2.0 Score 6.5 of 10 (medium)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 287

Summary

CVE-2024-11208 is a newly disclosed vulnerability affecting Apereo CAS 6.6. This issue is described as problematic and involves manipulating the /login?service functionality, resulting in session expiration. Attacks can be executed remotely, but with a high degree of complexity. The exploitation process is reportedly difficult, but a public disclosure of the exploit exists, increasing the risk. Despite early notification to the vendor, they have yet to respond.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share