Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5230

Опубликовано: 30 янв. 2020
Источник: nvd
CVSS3: 7.7
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape working directories and write files to other locations. In addition, Opencast's Id.toString(…) vs Id.compact(…) behavior, the latter trying to mitigate some of the file system problems, can cause errors due to identifier mismatch since an identifier may unintentionally change. This issue is fixed in Opencast 7.6 and 8.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apereo:opencast:*:*:*:*:*:*:*:*
Версия до 7.6 (исключая)
cpe:2.3:a:apereo:opencast:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00327
Низкий

7.7 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-99
CWE-74

Связанные уязвимости

CVSS3: 7.7
github
около 6 лет назад

Unsafe Identifiers in Opencast

EPSS

Процентиль: 55%
0.00327
Низкий

7.7 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-99
CWE-74