PT-2020-18327 · Opencast Community · Opencast

Moderatelkiesow

·

Published

2020-01-30

·

Updated

2020-02-10

·

CVE-2020-5231

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Opencast versions prior to 7.6 Opencast versions prior to 8.1
Description The issue allows users with the role ROLE COURSE ADMIN to create new users not including the role ROLE ADMIN using the "user-utils" endpoint. ROLE COURSE ADMIN is a non-standard role in Opencast, referenced only in the security configuration, and its name implies it should be for a specific course admin, not allowing user creation. This issue is fixed in versions 7.6 and 8.1, which ship a new default security configuration.
Recommendations For Opencast versions prior to 7.6, update to version 7.6 or later. For Opencast versions prior to 8.1, update to version 8.1 or later. As a temporary workaround, consider removing all instances of ROLE COURSE ADMIN in your organization's security configuration (etc/security/mh default org.xml by default).

Exploit

Fix

Improper Authorization

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5231
GHSA-94QW-R73X-J7HG

Affected Products

Opencast