GHSA-q39c-5vh5-vw2p
HIGHCVE-2020-27178Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
- Affected
- >= 6.2.0, < 6.2.4, >= 6.0.0, <= 6.1.7.1, >= 5.3.0, < 5.3.16
- Fixed in
- 6.2.4
- Weakness
- CWE-287
- Published
- 2021-08-02
- Source
- github