Apereo CAS
cpe:2.3:a:apereo:central_authentication_service:*:*:*:*:*:*:*
- 5.2.6
A denial-of-service vulnerability has been identified in Apereo CAS version 5.2.6. This issue arises in the ResponseEntity function of the ManageRegisteredServicesMultiActionController class, where inefficient regular expression processing can be exploited to create a denial-of-service condition. The vulnerability can be triggered remotely.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to become unresponsive or slow due to the regular expression engine being overwhelmed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.