This is an Apereo CAS project vulnerability disclosure, describing an issue in CAS's attempts to deserialize objects via the Apache Commons Collections library. The attack vector specifically applies to all deployments of CAS `v4.1.x` and `v4.2.x` deployments where the out-of-the-box default configuration of CAS is used for managing object serialization, encryption and signing of data.
Please review the linked instructions to understand the impact of this vulnerability on your deployments, and ways you can patch and prevent the attack: http://bit.ly/1Vydu53 Misagh -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/83872f1c.00002780.0000000a%40MMOAYYED.unicon.net. For more options, visit https://groups.google.com/a/apereo.org/d/optout.
