CVE-2020-26234
- EPSS 0.08%
- Veröffentlicht 08.12.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:36
Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of Opencast's HTTP requests. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is...
CVE-2020-5231
- EPSS 0.23%
- Veröffentlicht 30.01.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:43
In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE_ADMIN. ROLE_COURSE_ADMIN is a non-standard role in Opencast which is referenced neither in the docum...
- EPSS 0.3%
- Veröffentlicht 30.01.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:40
In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous...
CVE-2020-5230
- EPSS 0.33%
- Veröffentlicht 30.01.2020 21:15:15
- Zuletzt bearbeitet 21.11.2024 05:33:43
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an a...
CVE-2020-5222
- EPSS 0.26%
- Veröffentlicht 30.01.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:33:42
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers...
CVE-2020-5229
- EPSS 0.15%
- Veröffentlicht 30.01.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:43
Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted using the username instead of a random salt, causing hashes for users with the same username and pass...
CVE-2020-5228
- EPSS 0.34%
- Veröffentlicht 30.01.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:43
Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This le...
CVE-2017-1000221
- EPSS 0.22%
- Veröffentlicht 17.11.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access...