{"id":"GHSA-q39c-5vh5-vw2p","summary":"Improper Authentication in Apereo CAS","details":"Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.","aliases":["CVE-2020-27178"],"modified":"2024-02-17T05:35:20.937396Z","published":"2021-08-02T16:47:10Z","database_specific":{"nvd_published_at":"2020-10-16T16:15:00Z","cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-07-26T18:43:04Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27178"},{"type":"WEB","url":"https://apereo.github.io/2020/10/14/gauthvuln"}],"affected":[{"package":{"name":"org.apereo.cas:cas-server-webapp","ecosystem":"Maven","purl":"pkg:maven/org.apereo.cas/cas-server-webapp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"fixed":"5.3.16"}]}],"versions":["5.3.0","5.3.1","5.3.10","5.3.11","5.3.12","5.3.12.1","5.3.13","5.3.14","5.3.15","5.3.15.1","5.3.2","5.3.3","5.3.4","5.3.5","5.3.6","5.3.7","5.3.8","5.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-q39c-5vh5-vw2p/GHSA-q39c-5vh5-vw2p.json"}},{"package":{"name":"org.apereo.cas:cas-server-webapp","ecosystem":"Maven","purl":"pkg:maven/org.apereo.cas/cas-server-webapp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.1.7.2"}]}],"versions":["6.0.0","6.0.1","6.0.2","6.0.3","6.0.4","6.0.5","6.0.5.1","6.0.6","6.0.7","6.0.8","6.0.8.1","6.1.0","6.1.0-RC1","6.1.0-RC2","6.1.0-RC3","6.1.0-RC4","6.1.0-RC5","6.1.0-RC6","6.1.1","6.1.2","6.1.3","6.1.4","6.1.5","6.1.6","6.1.7","6.1.7.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.1.7.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-q39c-5vh5-vw2p/GHSA-q39c-5vh5-vw2p.json"}},{"package":{"name":"org.apereo.cas:cas-server-webapp","ecosystem":"Maven","purl":"pkg:maven/org.apereo.cas/cas-server-webapp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.4"}]}],"versions":["6.2.0","6.2.1","6.2.2","6.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-q39c-5vh5-vw2p/GHSA-q39c-5vh5-vw2p.json"}},{"package":{"name":"org.apereo.cas:cas-server-support-otp-mfa-core","ecosystem":"Maven","purl":"pkg:maven/org.apereo.cas/cas-server-support-otp-mfa-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"fixed":"5.3.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-q39c-5vh5-vw2p/GHSA-q39c-5vh5-vw2p.json"}},{"package":{"name":"org.apereo.cas:cas-server-support-otp-mfa-core","ecosystem":"Maven","purl":"pkg:maven/org.apereo.cas/cas-server-support-otp-mfa-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.1.7.2"}]}],"versions":["6.0.0","6.0.1","6.0.2","6.0.3","6.0.4","6.0.5","6.0.5.1","6.0.6","6.0.7","6.0.8","6.0.8.1","6.1.0","6.1.0-RC1","6.1.0-RC2","6.1.0-RC3","6.1.0-RC4","6.1.0-RC5","6.1.0-RC6","6.1.1","6.1.2","6.1.3","6.1.4","6.1.5","6.1.6","6.1.7","6.1.7.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.1.7.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-q39c-5vh5-vw2p/GHSA-q39c-5vh5-vw2p.json"}},{"package":{"name":"org.apereo.cas:cas-server-support-otp-mfa-core","ecosystem":"Maven","purl":"pkg:maven/org.apereo.cas/cas-server-support-otp-mfa-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.4"}]}],"versions":["6.2.0","6.2.1","6.2.2","6.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-q39c-5vh5-vw2p/GHSA-q39c-5vh5-vw2p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}