7.7
CWE
74 99
Advisory Published
Updated

CVE-2020-5230: Opencast uses unsafe identifiers

First published: Thu Jan 30 2020(Updated: )

Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape working directories and write files to other locations. In addition, Opencast's Id.toString(…) vs Id.compact(…) behavior, the latter trying to mitigate some of the file system problems, can cause errors due to identifier mismatch since an identifier may unintentionally change. This issue is fixed in Opencast 7.6 and 8.1.

Credit: security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
Apereo Opencast<7.6
Apereo Opencast=8.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-5230?

    CVE-2020-5230 is a vulnerability in Opencast before 8.1 and 7.6 that allows almost arbitrary identifiers for media packages and elements to be used.

  • What is the severity of CVE-2020-5230?

    The severity of CVE-2020-5230 is high, with a severity value of 7.5.

  • How does CVE-2020-5230 impact security?

    CVE-2020-5230 can be problematic for operation and security since it allows almost arbitrary identifiers for media packages and elements, which may lead to an attacker being able to escape working directories.

  • How can I check if I am affected by CVE-2020-5230?

    If you are using Opencast version before 8.1 or 7.6, you may be affected by CVE-2020-5230.

  • How can I fix CVE-2020-5230?

    To fix CVE-2020-5230, it is recommended to upgrade Opencast to version 8.1 or 7.6, depending on the version you are currently using.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203