First published: Fri Nov 17 2017(Updated: )
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLE_USER will have access to recordings published only for ROLE_USER_X.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apereo Opencast | <=2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000221 is a vulnerability in Opencast 2.2.3 and older versions that allows users to bypass access control by matching part of the user name used for the access restriction.
CVE-2017-1000221 is considered a medium severity vulnerability with a CVSS score of 6.5.
CVE-2017-1000221 affects Opencast versions 2.2.3 and older, where if user names overlap, the access control for the search service used for publication to media modules and players is handled incorrectly.
To fix CVE-2017-1000221, it is recommended to upgrade to a version of Opencast that is not affected by this vulnerability.
More information about CVE-2017-1000221 can be found in the reference link: https://opencast.jira.com/browse/MH-11862.