MEDIUM
Opencast users with ROLE_COURSE_ADMIN can create new users
Published Jan 30, 2020
6.5
MEDIUMCVSS 3.1
EPSS 0.63%
Description
In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE_ADMIN. ROLE_COURSE_ADMIN is a non-standard role in Opencast which is referenced neither in the documentation nor in any code (except for tests) but only in the security configuration. From the name – implying an admin for a specific course – users would never expect that this role allows user creation. This issue is fixed in 7.6 and 8.1 which both ship a new default security configuration.
Affected products
-
- Version < 7.6StatusaffectedConstraints-
- Version >= 8.0, < 8.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://github.com/advisories/GHSA-94qw-r73x-j7hg Advisory
- https://github.com/opencast/opencast/commit/72fad0031d8a82c860e2bde0b27570c5042320ee x_refsource_MISCPatch
- https://github.com/opencast/opencast/security/advisories/GHSA-94qw-r73x-j7hg x_refsource_CONFIRMExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-5231
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-94qw-r73x-j7hg | Advisory | |
| https://github.com/opencast/opencast/commit/72fad0031d8a82c860e2bde0b27570c5042320ee | x_refsource_MISCPatch | |
| https://github.com/opencast/opencast/security/advisories/GHSA-94qw-r73x-j7hg | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-5231 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 30, 2020
Updated Aug 4, 2024
Reserved Jan 2, 2020
Link CVE-2020-5231
CISA Vulnrichment
GHSA-94QW-R73X-J7HG Updated n/a