CVE-2020-5222: Hard-Coded Key Used For Remember-me Token in OpenCast
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials. This problem is fixed in Opencast 7.6 and Opencast 8.1
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenCastto a version that resolves this vulnerability.Fixed in 7.6 - Upgrade
Upgrade
OpenCastto a version that resolves this vulnerability.Fixed in 8.1
Event History
Frequently Asked Questions
What is CVE-2020-5222?
CVE-2020-5222 is a vulnerability in Opencast versions before 7.6 and 8.1 that enables a remember-me cookie based on a hash created from the username, password, and an additional system key.
How does CVE-2020-5222 affect Opencast?
CVE-2020-5222 affects Opencast versions before 7.6 and 8.1, allowing an attacker who gains access to a remember-me token for one server to access all servers that use the same credentials.
What is the severity of CVE-2020-5222?
CVE-2020-5222 has a severity level of 8.8 (high).
How can I fix CVE-2020-5222?
To fix CVE-2020-5222, you should update Opencast to version 7.6 or 8.1, which include the necessary security patches.
Where can I find more information about CVE-2020-5222?
You can find more information about CVE-2020-5222 in the Opencast GitHub commit and the Opencast security advisory mentioned in the references.