{"id":"CVE-2012-5583","details":"phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.","modified":"2026-04-10T03:42:32.414538Z","published":"2014-06-06T14:55:03Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/51818"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81208"},{"type":"WEB","url":"https://github.com/Jasig/phpCAS/blob/master/docs/ChangeLog"}],"schema_version":"1.7.5"}