CVE-2017-1000217

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
17/11/2017
Last modified:
20/04/2025

Description

Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opencast:opencast:*:*:*:*:*:*:*:* 2.3.2 (including)