Skip to content

Commit 6ddfe61

Browse files
1 parent bd123cf commit 6ddfe61

File tree

1 file changed

+30
-5
lines changed

1 file changed

+30
-5
lines changed

advisories/unreviewed/2025/04/GHSA-8rx4-fxq5-vj4v/GHSA-8rx4-fxq5-vj4v.json renamed to advisories/github-reviewed/2025/04/GHSA-8rx4-fxq5-vj4v/GHSA-8rx4-fxq5-vj4v.json

Lines changed: 30 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-8rx4-fxq5-vj4v",
4-
"modified": "2025-04-27T21:34:48Z",
4+
"modified": "2025-11-06T15:14:55Z",
55
"published": "2025-04-27T21:34:48Z",
66
"aliases": [
77
"CVE-2025-3985"
88
],
9+
"summary": "Apereo CAS has inefficient regular expression complexity",
910
"details": "A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\\webapp-mgmt\\cas-management-webapp-support\\src\\main\\java\\org\\apereo\\cas\\mgmt\\services\\web\\ManageRegisteredServicesMultiActionController.java. The manipulation of the argument Query leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
1011
"severity": [
1112
{
@@ -14,15 +15,39 @@
1415
},
1516
{
1617
"type": "CVSS_V4",
17-
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
19+
}
20+
],
21+
"affected": [
22+
{
23+
"package": {
24+
"ecosystem": "Maven",
25+
"name": "org.apereo.cas:cas-management-webapp-support"
26+
},
27+
"ranges": [
28+
{
29+
"type": "ECOSYSTEM",
30+
"events": [
31+
{
32+
"introduced": "0"
33+
},
34+
{
35+
"last_affected": "5.2.6"
36+
}
37+
]
38+
}
39+
]
1840
}
1941
],
20-
"affected": [],
2142
"references": [
2243
{
2344
"type": "ADVISORY",
2445
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3985"
2546
},
47+
{
48+
"type": "PACKAGE",
49+
"url": "https://github.com/apereo/cas"
50+
},
2651
{
2752
"type": "WEB",
2853
"url": "https://vuldb.com/?ctiid.306321"
@@ -45,8 +70,8 @@
4570
"CWE-400"
4671
],
4772
"severity": "MODERATE",
48-
"github_reviewed": false,
49-
"github_reviewed_at": null,
73+
"github_reviewed": true,
74+
"github_reviewed_at": "2025-11-06T15:14:55Z",
5075
"nvd_published_at": "2025-04-27T21:15:16Z"
5176
}
5277
}

0 commit comments

Comments
 (0)