Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.
{ "binaries": [ { "binary_name": "php-cas", "binary_version": "1.3.3-2ubuntu1+esm1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-1000071.json"
{ "binaries": [ { "binary_name": "php-cas", "binary_version": "1.3.3-4" } ] }