CVE-2025-54380

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would incorrectly send the hashed global system account credentials (ie: org.opencastproject.security.digest.user and org.opencastproject.security.digest.pass) when attempting to fetch mediapackage elements included in a mediapackage XML file. A previous CVE prevented many cases where the credentials were inappropriately sent, but not all. Anyone with ingest permissions could cause Opencast to send its hashed global system account credentials to a url of their choosing. This issue is fixed in Opencast 17.6.
Configurations

No configuration.

History

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) Opencast es una plataforma gratuita de código abierto que facilita la gestión de contenido educativo de audio y vídeo. Antes de la versión 17.6, Opencast enviaba incorrectamente las credenciales de la cuenta global del sistema con hash (es decir, org.opencastproject.security.digest.user y org.opencastproject.security.digest.pass) al intentar obtener elementos de mediapackage incluidos en un archivo XML de mediapackage. Una CVE anterior evitó muchos casos de envío indebido de credenciales, pero no todos. Cualquier persona con permisos de ingesta podía hacer que Opencast enviara sus credenciales de la cuenta global del sistema con hash a una URL de su elección. Este problema se solucionó en Opencast 17.6.

26 Jul 2025, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-26 04:16

Updated : 2025-07-29 14:14


NVD link : CVE-2025-54380

Mitre link : CVE-2025-54380

CVE.ORG link : CVE-2025-54380


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-522

Insufficiently Protected Credentials