CVE-2018-16153
Java vulnerability analysis and mitigation

Overview

An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. The system sends digest credentials during authentication attempts to arbitrary external services in some situations when trying to access files listed in a media package, regardless of whether the target is part of the Opencast cluster or not (GitHub Advisory, NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (High) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The issue is related to insufficiently protected credentials (CWE-522) where the system would attempt to authenticate against any external services using the global system user's credentials (GitHub Advisory).

Impact

While previous mitigations prevented clear text authentications for such requests (e.g., HTTP Basic authentication), with enough malicious intent, even hashed credentials could potentially be broken. This could lead to unauthorized access to system credentials (GitHub Advisory).

Mitigation and workarounds

The issue has been fixed in Opencast 10.6, which now only sends authentication requests to servers that are part of the Opencast cluster, preventing external services from receiving any form of authentication attempt. No workaround is available for earlier versions (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management