CVE-2025-61788
- EPSS 0.06%
- Veröffentlicht 08.10.2025 18:15:35
- Zuletzt bearbeitet 09.10.2025 16:00:05
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, the paella would include and render some user inputs (metadata like title, description, etc.) unfiltered and u...
CVE-2025-61906
- EPSS 0.04%
- Veröffentlicht 08.10.2025 18:15:35
- Zuletzt bearbeitet 09.10.2025 15:59:51
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, in some situations, Opencast's editor may publish a video without notifying the user. This may lead to users a...
CVE-2025-55202
- EPSS 0.07%
- Veröffentlicht 29.08.2025 15:35:35
- Zuletzt bearbeitet 03.09.2025 16:09:32
Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config module are insufficient, still partia...
CVE-2025-54380
- EPSS 0.04%
- Veröffentlicht 26.07.2025 03:28:25
- Zuletzt bearbeitet 26.08.2025 16:57:00
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would incorrectly send the hashed global system account credentials (ie: org.opencastproject.security.digest.us...
CVE-2024-52797
- EPSS 0.36%
- Veröffentlicht 21.11.2024 11:15:35
- Zuletzt bearbeitet 28.10.2025 20:15:46
Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch integration may generate syntactically invalid Elasticsearch queries in relation to previously accep...
CVE-2017-1000217
- EPSS 0.69%
- Veröffentlicht 17.11.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.