CVE-2024-4399 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Apereo Central Authentication Service (CAS) products. The vulnerability stems from a lack of parameter validation, allowing unauthenticated attackers to initiate requests from the server. With a CVSS score of 9.1, it presents a high risk of compromise to confidentiality and integrity. While not currently in CISA's KEV catalog, a Nuclei template for exploitation exists, and the vulnerability has garnered significant community discussion, indicating potential for future active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:apereo:central_authentication_service:-:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.