Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.
{ "binaries": [ { "binary_name": "php-cas", "binary_version": "1.3.3-2ubuntu1+esm1" } ] }
{ "binaries": [ { "binary_name": "php-cas", "binary_version": "1.3.3-4" } ] }