CVE-2020-27178: Apereo Central Authentication Service

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.

Affected products

  • Apereo Central Authentication Service: from 5.3.0, before 5.3.16 (fixed in 5.3.16); from 6.0.0, before 6.1.7.2 (fixed in 6.1.7.2); from 6.2.0, before 6.2.4 (fixed in 6.2.4); version 6.3.0 only

Published 2020-10-16. Last modified 2026-06-17.