PT-2025-30942 · Opencast · Opencast

Lkiesow

·

Published

2021-12-14

·

Updated

2025-07-26

·

CVE-2025-54380

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Opencast versions prior to 17.6
Description Opencast incorrectly sent hashed global system account credentials (org.opencastproject.security.digest.user and org.opencastproject.security.digest.pass) when fetching mediapackage elements included in a mediapackage XML file. Individuals with ingest permissions could cause Opencast to send these credentials to a URL of their choosing. A previous issue prevented some instances of this, but not all.
Recommendations Upgrade to Opencast version 17.6 or later.

Exploit

Fix

Information Disclosure

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-54380
GHSA-HCXX-MP6G-6GR9
GHSA-J63H-HMGW-X4J7

Affected Products

Opencast