CVE-2025-3986
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 27, 2025
Updated: Apr 29, 2025
CWE ID 1333
CWE ID 400
Summary
CVE-2025-3986 is a newly disclosed vulnerability affecting Apereo CAS 5.2.6. The issue lies within the file CasConfigurationMetadataServerController.java, where inefficient regular expression complexity can be triggered by manipulating the Name argument. This vulnerability poses a remote exploit risk and has already been made public. Despite early notification, the vendor has yet to provide a response.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cas