CVE-2020-5222
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
30/01/2020
Last modified:
05/02/2020
Description
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials. This problem is fixed in Opencast 7.6 and Opencast 8.1
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apereo:opencast:*:*:*:*:*:*:*:* | 7.6 (excluding) | |
| cpe:2.3:a:apereo:opencast:8.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



