CVE-2020-5222
Published
CVSS v3
6.8
MEDIUM
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT
Description
Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials. This problem is fixed in Opencast 7.6 and Opencast 8.1
The free and open source solution for automated video capture and distribution at scale.