CVE-2020-5222

Published
View on NVD ↗
CVSS v3
6.8
MEDIUM
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials. This problem is fixed in Opencast 7.6 and Opencast 8.1

The free and open source solution for automated video capture and distribution at scale.
GitHubGitHub
495