Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Central Authentication System (CAS) Server - Moderately critical - Open redirect - SA-CONTRIB-2026-135

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Central Authentication System (CAS) Server - Moderately critical - Open redirect - SA-CONTRIB-2026-135


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Central Authentication System (CAS) Server - Moderately critical - Open redirect - SA-CONTRIB-2026-135
  • Date: Wed, 9 Sep 2026 17:15:41 +0000
  • Arc-authentication-results: i=2; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=LDmyiw9b; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=gXCIoP9e; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=LDmyiw9b; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=gXCIoP9e; arc=none smtp.remote-ip=54.240.27.115
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org E42876143C
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org E7B2C607C4
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788976486; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=o9tPsje++gOmYW4pqqpmmUw1mEw5utPotDKNmOt5kas=; b=XxzUx9frfCe9CUep82sjfuk4QcKfbS1rzcb4UYfZ+jZJOChdbRX5Zs05CL5Sy52o/H8K f8I0gyFlIH6G8k+bUgeSDVGtBPYa0vd55KX8banA7rIA070DxoFTTn9L27K8K32mHNXiI MLL9VZp9oiUlm3F0mmcz8je1xAXFTI9QMy6eXn5dC3yZn+ufCx9C29x+n/TyDLcA9pnmB 3fc4cv5ru3knl0BQKAXDLzmFDLh/JS2y+257ssKR88qQFZqpQ4YZ9Da1jEDJigQoZJOdE xtReU9J5VLNhjeEjXMnseELvR5ifwuouNGE5oGvQouXvEBUVukMI+ilAtPCJ6FuX8Qw==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974143; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=oMBxhkzg87X4UwPXpgjHlTcQn6KPO0WB0iHWCplkhFM=; b=MTWUHv0iq8IiAJb2B7gODQ5YTNzX+c9oWezU4oiIZuUozUa3lZOoEkXLISS7oTvrPaQy /b8LjhVo20Wh1M6umtrRkeOUOCXBsjtf/+lIpael7SJfq4on7JDCghea04VfchwWmFjxs l7Mwi32WskrAL/vQ+aeQvV86FN7HqYmz6N7o1g51pW0eJ62cfY1l37h5z++Ds8fysfWbL hN6l4fByIquoPfS7LnGZe8vEFqKt0gYIv2MitQRdpH73nTd5YCJiPzsjv99Y+jbg/6l51 tiiuNF1wQGXD2cM65SYaia8OcLnaDVHgoh5dLMVJzzYW6kXnzWf9aFZNzhgOeE6TY0g==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788976486; b=TDgQ6xLOrJaaUXrfugR2gPhSd9Cd5A6ofKZsC8d6DqoCFej4vj+sC3/WUnjk9+Svs/89 ktnDGCKQltdwAT4yGx2O87XdGB4Vl6/eqXfBTRx4/0Ft8EEk1wZ7YB25QGeN4/wGvuOOt ZxqosDP03aC8ceMNZncXf6IhBI7y/5jo44yy5DLPXadzkaZXKr7qtGJAtjR2QkGhx3ePg FU1AmXkxjogtC0QtZWhQvMW3wPtSNL7JgJZ4qgC3C2YGjWwgsK/hOkti+Xtl/1eY3vBeu Y5Sza+7CBBU+p1dppJXk2+pNKv7D+TiYXnk42O2Wb/PC/rla7hb4Y4+EcouvVLWcwiA==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974143; b=TV4DRbvLURSmBlvSaNnMXVGBCuHqOiKmxQipmBOX27/CDAR5d2YkZtsbpIANTCLg2qY+ AaChc68nDhYMLPaJlaj6bKR8IsfKVEZcgOkF2GQDMb6jFvOcR+wVruX3dzJ7yWOfeMHYn ZAEVxJboCBU7p2afh5WHAlKyiitAX/A4n/+bVME2pSGAEFxPR/G1Vz7DCwaj5BYV5Oi5e am1zhOT0gog1rbc6dejIHtedVUPYjZrtcFzXcw5iuIU/UwMfST/yrZohGMKeW7/amTWdp rOMhitORUbZ6QJwJ7Yhruh+kvOFj4nKtelBIpEoc9iyl8Hml+ql7jamUOFz0zqxmmQg==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/H6DUNYN56DIBTANIJDQHOBOPLYRDSJRH/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=OUZ82b46; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=LDmyiw9b; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=gXCIoP9e; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-135

Project: Central Authentication System (CAS) Server [1]
Date: 2026-September-09
Security risk: *Moderately critical* 10 ∕ 25
AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:All [2]
Vulnerability: Open redirect

Affected versions: <2.0.4 || >=2.1.0 <2.1.3
CVE IDs: CVE-2026-87937
Description: 
This module enables you to turn a Drupal install into the Central
Authentication System (CAS) Server. It makes your database the primary
location for other systems to use for authentication in a SSO environment.

The module doesn't sufficiently check the service URL used to redirect the
user during logout, leading to an open redirect.

This vulnerability is mitigated by the fact that an attacker must convince a
user to click a specially crafted link. The vulnerability cannot be exploited
without user interaction and does not allow an attacker to directly
compromise the CAS server or bypass authentication.

Solution: 
Install the latest version of Central Authentication System (CAS) Server
module:

* If you use the 2.0.x branch, upgrade to CAS Server 2.0.4 [3].
* If you use the 2.1.x branch, upgrade to CAS Server 2.1.3 [4]

Reported By: 
* Kalle Kipinä (kekkis) [5]

Fixed By: 
* Ted Cooper (elc) [6]

Coordinated By: 
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Jess (xjm) [9] of the Drupal Security Team
* Swan Kalata (akalata) [10] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [11]

[1] https://www.drupal.org/project/cas_server
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/cas_server/releases/2.0.4
[4] https://www.drupal.org/project/cas_server/releases/2.1.3
[5] https://www.drupal.org/u/kekkis
[6] https://www.drupal.org/u/elc
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/xjm
[10] https://www.drupal.org/u/akalata
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621463

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Central Authentication System (CAS) Server - Moderately critical - Open redirect - SA-CONTRIB-2026-135, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang