PT-2020-18327 · Opencast Community · Opencast
Moderatelkiesow
·
Published
2020-01-30
·
Updated
2020-02-10
·
CVE-2020-5231
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Opencast versions prior to 7.6
Opencast versions prior to 8.1
Description
The issue allows users with the role
ROLE COURSE ADMIN to create new users not including the role ROLE ADMIN using the "user-utils" endpoint. ROLE COURSE ADMIN is a non-standard role in Opencast, referenced only in the security configuration, and its name implies it should be for a specific course admin, not allowing user creation. This issue is fixed in versions 7.6 and 8.1, which ship a new default security configuration.Recommendations
For Opencast versions prior to 7.6, update to version 7.6 or later.
For Opencast versions prior to 8.1, update to version 8.1 or later.
As a temporary workaround, consider removing all instances of
ROLE COURSE ADMIN in your organization's security configuration (etc/security/mh default org.xml by default).Exploit
Fix
Improper Authorization
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opencast