{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-01T20:07:05.233","vulnerabilities":[{"cve":{"id":"CVE-2023-4612","sourceIdentifier":"cvd@cert.pl","published":"2023-11-09T14:15:08.183","lastModified":"2026-06-17T06:38:13.390","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability."},{"lang":"es","value":"Vulnerabilidad de autenticación incorrecta en Apereo CAS en jakarta.servlet.http.HttpServletRequest.getRemoteAddr permite omitir la autenticación multifactor. Este problema afecta a CAS: hasta 7.0.0-RC7. Se desconoce si en las nuevas versiones se solucionará el problema. Para la fecha de publicación no existe ningún parche y el proveedor no lo trata como una vulnerabilidad."}],"affected":[{"source":"cvd@cert.pl","affectedData":[{"vendor":"Apereo Foundation","product":"CAS","defaultStatus":"unknown","collectionURL":"https://www.apereo.org/projects/cas","versions":[{"version":"0","lessThanOrEqual":"7.0.0-RC7","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-11-17T19:57:40.527274Z","id":"CVE-2023-4612","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cvd@cert.pl","type":"Secondary","description":[{"lang":"en","value":"CWE-302"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.0","matchCriteriaId":"E724510C-AE63-4436-90F9-D688D9F1BF81"},{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc1:*:*:*:*:*:*","matchCriteriaId":"21DF5E84-0799-4301-BDE0-FD4DE43845E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc2:*:*:*:*:*:*","matchCriteriaId":"97724FE8-EF13-4B89-BD38-3D1E8489B932"},{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc3:*:*:*:*:*:*","matchCriteriaId":"0E231FEB-5DAF-4A89-BABF-51F248C7B1AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc4:*:*:*:*:*:*","matchCriteriaId":"9CE1DFD4-C7AD-4811-AE6B-F674F5C00BCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc5:*:*:*:*:*:*","matchCriteriaId":"55798B47-3A4A-4261-BE73-CA1B7A53390B"},{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc6:*:*:*:*:*:*","matchCriteriaId":"141E626C-5B40-4BAA-A4F6-5057F98E6F1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc7:*:*:*:*:*:*","matchCriteriaId":"3D2D6BDE-6F2E-47F3-8C71-0D27EE567AF4"}]}]}],"references":[{"url":"https://cert.pl/en/posts/2023/11/CVE-2023-4612/","source":"cvd@cert.pl","tags":["Third Party Advisory"]},{"url":"https://cert.pl/posts/2023/11/CVE-2023-4612/","source":"cvd@cert.pl","tags":["Third Party Advisory"]},{"url":"https://cert.pl/en/posts/2023/11/CVE-2023-4612/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://cert.pl/posts/2023/11/CVE-2023-4612/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}