
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. The system sends digest credentials during authentication attempts to arbitrary external services in some situations when trying to access files listed in a media package, regardless of whether the target is part of the Opencast cluster or not (GitHub Advisory, NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (High) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The issue is related to insufficiently protected credentials (CWE-522) where the system would attempt to authenticate against any external services using the global system user's credentials (GitHub Advisory).
While previous mitigations prevented clear text authentications for such requests (e.g., HTTP Basic authentication), with enough malicious intent, even hashed credentials could potentially be broken. This could lead to unauthorized access to system credentials (GitHub Advisory).
The issue has been fixed in Opencast 10.6, which now only sends authentication requests to servers that are part of the Opencast cluster, preventing external services from receiving any form of authentication attempt. No workaround is available for earlier versions (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”