PT-2022-26189 · Opencast · Opencast
Gregorydlogan
·
Published
2022-11-28
·
Updated
2022-12-01
·
CVE-2022-41965
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Opencast versions prior to 12.5
Description
The vulnerability in Opencast's Paella authentication page allows attackers to redirect authenticated users to arbitrary URLs, potentially facilitating phishing attacks or other security issues. This could enable attackers to redirect users to sites outside of their Opencast install.
Recommendations
For versions prior to 12.5, update to Opencast 12.5 or newer to resolve the issue. As a temporary workaround, consider restricting access to the Paella authentication page until a patch is applied.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencast