PT-2021-8817 · Apereo · Apereo Opencast

Gregorydlogan

·

Published

2021-12-14

·

Updated

2023-12-14

·

CVE-2018-16153

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apereo Opencast versions 4.x through 10.x before 10.6
Description An issue was discovered in Apereo Opencast where it sends system digest credentials during authentication attempts to arbitrary external services in some situations. This occurs when Opencast tries to authenticate against any external services listed in a media package, sending the global system user's credentials, regardless of the target being part of the Opencast cluster or not. Although previous mitigations prevented clear text authentications for such requests, hashed credentials can still be broken with enough malicious intent.
Recommendations For Apereo Opencast versions 4.x through 10.x before 10.6, update to version 10.6, which now sends authentication requests only against servers that are part of the Opencast cluster, preventing external services from getting any form of authentication attempt. At the moment, there is no other information about additional mitigation measures for these versions.

Fix

Information Disclosure

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2018-16153
GHSA-HCXX-MP6G-6GR9

Affected Products

Apereo Opencast