This is an Apereo CAS project vulnerability disclosure, describing an
issue in CAS's attempts to deserialize objects via the Apache Commons
Collections library. The attack vector specifically applies to all
deployments of CAS `v4.1.x` and `v4.2.x` deployments where the
out-of-the-box default configuration of CAS is used for managing object
serialization, encryption and signing of data.

 

Please review the linked instructions to understand the impact of this
vulnerability on your deployments, and ways you can patch and prevent the
attack:

 

http://bit.ly/1Vydu53

 

Misagh

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/83872f1c.00002780.0000000a%40MMOAYYED.unicon.net.
For more options, visit https://groups.google.com/a/apereo.org/d/optout.

Reply via email to