CVE-2024-11209
CVSS 2.0 Score 6.5 of 10 (medium)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 287
Summary
CVE-2024-11208 is a newly disclosed vulnerability affecting Apereo CAS 6.6. This issue is described as problematic and involves manipulating the /login?service functionality, resulting in session expiration. Attacks can be executed remotely, but with a high degree of complexity. The exploitation process is reportedly difficult, but a public disclosure of the exploit exists, increasing the risk. Despite early notification to the vendor, they have yet to respond.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cas