Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2019-13343 Vulnerability in maven package com.butor:portal
CVE-2021-32736 Vulnerability in npm package think-helper
CVE-2022-0436 Vulnerability in npm package grunt
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-mysql-cdc
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-webflux