Home Embedded Vulns General Vulns

CVE-2020-5222

MEDIUM 6.8

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date January 30, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials. This problem is fixed in Opencast 7.6 and Opencast 8.1

Potentially Affected Vendors