PT-2025-30942 · Opencast · Opencast
Lkiesow
·
Published
2021-12-14
·
Updated
2025-07-26
·
CVE-2025-54380
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Opencast versions prior to 17.6
Description
Opencast incorrectly sent hashed global system account credentials (
org.opencastproject.security.digest.user and org.opencastproject.security.digest.pass) when fetching mediapackage elements included in a mediapackage XML file. Individuals with ingest permissions could cause Opencast to send these credentials to a URL of their choosing. A previous issue prevented some instances of this, but not all.Recommendations
Upgrade to Opencast version 17.6 or later.
Exploit
Fix
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opencast