Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2014-4172 Details

Description

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137182.html CVEThird Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=759718 CVEThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1131350 CVEIssue TrackingThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/95673 CVEThird Party AdvisoryVDB Entry
https://github.com/Jasig/dotnet-cas-client/commit/f0e030014fb7a39e5f38469f43199dc590fd0e8d CVEPatchThird Party Advisory

see all 22 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')[email protected]

Affected Products

ProductVersions
apereo .net cas client
< 1.0.2

CPE

  • cpe:2.3:a:apereo:.net_cas_client:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
apereo java cas client
< 3.3.2

CPE

  • cpe:2.3:a:apereo:java_cas_client:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
apereo phpcas
< 1.3.3

CPE

  • cpe:2.3:a:apereo:phpcas:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
debian debian linux
7.0

CPE

  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
20

CPE

  • cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2014-4172
NVD Published Date:
Jan 24, 2020
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2014-4172 Details - Not Deferred