Changes to CAS Security Vulnerability Response

Apereo CAS is shortening the security disclosure grace window.

CAS Vulnerability Disclosure

Disclosure of a series of security issues with the Apereo CAS software.

CAS Vulnerability Disclosure

Disclosure of a series of security issues with the Apereo CAS software.

CAS OpenID Connect Vulnerability Disclosure

Disclosure of a security issue with the Apereo CAS software acting itself as an OpenID Connect provider.

Java CAS Client JWT Vulnerability Disclosure

Disclosure of a security issue with the Java CAS Client validating JWTs.

Apereo CAS - External Identity Providers

An overview of Apereo CAS' ability to register identity providers for external and delegated authentication attempts.

CAS JWT Authentication Vulnerability Disclosure

Disclosure of a security issue with the Apereo CAS software using JWT non-interactive authentication.

Performance improvements on the service registry

An overview of the work done on performance.