Description
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-5206 | The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page. |
References
| Link | Providers |
|---|---|
| https://github.com/gluxon/CVE-2018-13257 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:00:34.044Z
Reserved: 2018-07-05T00:00:00.000Z
Link: CVE-2018-13257
No data.
Status : Modified
Published: 2019-11-18T16:15:11.447
Modified: 2024-11-21T03:46:44.220
Link: CVE-2018-13257
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD