{"id":"CVE-2023-4612","summary":"MFA bypass in Apereo CAS","details":"Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.","modified":"2026-08-27T03:30:25.759235899Z","published":"2023-11-09T13:41:38.189Z","database_specific":{"cwe_ids":["CWE-302"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4612.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"7.0.0-RC7"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"7.0.0-RC7"}],"source":"DESCRIPTION"}],"cna_assigner":"CERT-PL"},"references":[{"type":"WEB","url":"https://www.apereo.org/projects/cas"},{"type":"ADVISORY","url":"https://cert.pl/en/posts/2023/11/CVE-2023-4612/"},{"type":"ADVISORY","url":"https://cert.pl/posts/2023/11/CVE-2023-4612/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4612.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4612"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apereo/cas","events":[{"introduced":"0"},{"fixed":"b1e65f89a4854e3690b68a52b0589ecbbbb1eb3f"},{"introduced":"3d85259c3615ba1e15ffab46757b8c3567821749"},{"last_affected":"d2930a9ee92f9530438f1887b8711a6a2a609f0d"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:apereo:central_authentication_service:*:*:*:*:*:*:*:*","cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc1:*:*:*:*:*:*","cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc2:*:*:*:*:*:*","cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc3:*:*:*:*:*:*","cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc4:*:*:*:*:*:*","cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc5:*:*:*:*:*:*","cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc6:*:*:*:*:*:*","cpe:2.3:a:apereo:central_authentication_service:7.0.0:rc7:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"7.0.0"},{"introduced":"7.0.0-rc1"},{"last_affected":"7.0.0-rc1"},{"introduced":"7.0.0-rc2"},{"last_affected":"7.0.0-rc2"},{"introduced":"7.0.0-rc3"},{"last_affected":"7.0.0-rc3"},{"introduced":"7.0.0-rc4"},{"last_affected":"7.0.0-rc4"},{"introduced":"7.0.0-rc5"},{"last_affected":"7.0.0-rc5"},{"introduced":"7.0.0-rc6"},{"last_affected":"7.0.0-rc6"},{"introduced":"7.0.0-rc7"},{"last_affected":"7.0.0-rc7"}]}}],"versions":["7.0.0-rc1","7.0.0-rc2","7.0.0-rc3","7.0.0-rc4","7.0.0-rc5","7.0.0-rc6","7.0.0-rc7","v7.0.0-RC9","v7.0.0-RC7","v6.6.0-RC2","v6.6.0-RC1","v6.5.0-RC4","v6.5.0-RC3","v6.5.0-RC2","v6.4.0-RC1","v6.3.0-RC5","v6.3.0-RC2","6.3.0-RC1","v6.2.0-RC5","v6.1.0-RC6","v6.1.0-RC5","v4.0.0-RC1","v3.5.1-RC1","v3.5.0","v3.5.0-RC2","v3.5.0-RC1","v3.4.11","3.4.11-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4612.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}