CVE-2017-1000221: Medium severity opencast vulnerability
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLEUSER will have access to recordings published only for ROLEUSERX.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1000221?
CVE-2017-1000221 is a vulnerability in Opencast 2.2.3 and older versions that allows users to bypass access control by matching part of the user name used for the access restriction.
What is the severity of CVE-2017-1000221?
CVE-2017-1000221 is considered a medium severity vulnerability with a CVSS score of 6.5.
How does CVE-2017-1000221 affect Opencast?
CVE-2017-1000221 affects Opencast versions 2.2.3 and older, where if user names overlap, the access control for the search service used for publication to media modules and players is handled incorrectly.
How can I fix CVE-2017-1000221?
To fix CVE-2017-1000221, it is recommended to upgrade to a version of Opencast that is not affected by this vulnerability.
Where can I find more information about CVE-2017-1000221?
More information about CVE-2017-1000221 can be found in the reference link: https://opencast.jira.com/browse/MH-11862.