VendorsApereocentral_authentication_service6.1.0
Vulnerabilities

Apereo Central Authentication Service (CAS) 6.1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2019-10754
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong.
Published 2019-09-23 · Modified
8.1EPSS 0.018