CVE-2025-3986

Description

A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6corecas-server-core-configuration-metadata-repositorysrcmainjavaorgapereocasmetadatarestCasConfigurationMetadataServerController.java. The manipulation of the argument Name leads to inefficient regular expression complexity. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.587

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-3986 are affected in Apereo - cas-server-core-configuration-metadata-repository 5.2.6Windows
Vulnerabilities CVE-2025-3986 are affected in Apereo - cas-server-core-configuration-metadata-repository for Linux 5.2.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234