Central Authentication System (CAS) Server
The module does not properly check the web address used to send users to a new page after they log out. Anyone visiting the site could trick a user into clicking a link that sends them to a malicious external website. They could not read any private information or change any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker can convince a user to click a specially crafted link.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Central Authentication System (CAS) Server to 2.0.4 or 2.1.3, whichever branch you are on.
For developers: what the fix changed
The fix validates the service URL during logout in the UserActionController class by checking it against the configuration helper. If the service is invalid it returns an error message.
src/Controller/UserActionController.php+6 −0 fix