Description
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hcxx-mp6g-6gr9 | Opencast publishes global system account credentials |
References
History
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-27T14:35:51.213Z
Reserved: 2018-08-29T00:00:00.000Z
Link: CVE-2018-16153
Updated: 2024-08-05T10:17:38.300Z
Status : Modified
Published: 2023-12-12T17:15:07.517
Modified: 2026-06-17T01:43:47.433
Link: CVE-2018-16153
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-522
Insufficiently Protected Credentials
Github GHSA