Impact
Opencast’s default security configuration allows a client‑selected JSESSIONID to be passed through the ;jsessionid URL path parameter. When a victim’s browser has no existing Opencast session cookie and subsequently authenticates, the supplied identifier persists as an authenticated session. This flaw permits the attacker to hijack the victim’s authenticated session, exposing the victim’s data and, if the victim holds administrative privileges, enabling a full administrative account takeover. The weakness is characterized by CWE‑384, Session Fixation.
Affected Systems
All Opencast platform releases prior to 19.7 and prior to 20.2 are vulnerable because the mh_default_org.xml security configuration accepts client‑provided JSESSIONID values. Versions 19.7 and 20.2 contain the necessary fix to prevent session fixation. Any installations running earlier versions are therefore exposed to the described risk.
Risk and Exploitability
The CVSS base score of 8.8 reflects a high‑severity vulnerability. The EPSS score is not available, so the exact network exploitation probability remains unclear (this lack of data is inferred). Because the flaw can be exploited simply by sending a crafted link to any victim with a fresh browser session, attackers do not need elevated privileges. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of an already‑known campaign targeting it. Nonetheless, the ability to hijack authentication sessions keeps the risk significant for any exposed deployment.
OpenCVE Enrichment