HIGH🇵🇱 Wersja polska

CVE-2020-5228

CVSS 7.6v3.1pub. 2020-01-30upd. 2024-11-21

Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This leads to users unknowingly handing out public access to events without their knowledge. The problem has been addressed in Opencast 7.6 and 8.1 where the OAI-PMH endpoint is configured to require users with `ROLE_ADMIN` by default. In addition to this, Opencast 9 removes the OAI-PMH publication from the default workflow, making the publication a conscious decision users have to make by updating their workflows.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
  • Apereo Opencast

    APP
    Apereo
    8.0< 7.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-43821CRITICAL9.9PL ✓same product

Apereo Opencast: ujawnienie lokalnych plików przez ingest media packages

CVE-2018-16153HIGH7.5same product

An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials du...

CVE-2021-43807HIGH7.5same product

Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 a...

CVE-2021-32623HIGH8.1same product

Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast...

CVE-2020-5230HIGH7.7same product

Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. Th...