It was discovered that php-pear-CAS contained a possible authentication bypass in validateCAS20.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0293.json"