Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcxx-mp6g-6gr9

Опубликовано: 14 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Opencast publishes global system account credentials

The issue was mostly mitigated before, drastically reducing the risk. See references below for more information.

Impact

Opencast before version 10.6 will try to authenticate against any external services listed in a media package when it is trying to access the files, sending the global system user's credentials, regardless of the target being part of the Opencast cluster or not.

Previous mitigations already prevented clear text authentications for such requests (e.g. HTTP Basic authentication), but with enough malicious intent, even hashed credentials can be broken.

Patches

Opencast 10.6 will now send authentication requests only against servers which are part of the Opencast cluster, preventing external services from getting any form of authentication attempt in the first place.

Workarounds

No workaround available.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.opencastproject:opencast-common

maven
Затронутые версииВерсия исправления

< 10.6

10.6

EPSS

Процентиль: 45%
0.00227
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.

EPSS

Процентиль: 45%
0.00227
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-522