CAS issues with 5.1.6

Cantor, Scott cantor.2 at osu.edu
Thu Sep 18 20:54:57 UTC 2025


> I assume this behavior is related to CVE-2025-41242 [1] as it
> does not seem to occur with 5.1.4. 

That change only affects tickets relayed with POST, which I don't think is common. I would expect literally no difference the traces otherwise.

The risky change is in 5.2 to get off a Spring class building the URLs and it hasn't shipped yet.

-- Scott




More information about the users mailing list