Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-41965
HistoryNov 28, 2022 - 12:00 a.m.

CVE-2022-41965 Opencast Authenticated OpenRedirect Vulnerability

2022-11-2800:00:00
CWE-601
GitHub_M
www.cve.org
2
opencast
vulnerability
openredirect
authentication
phishing
security issue

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

26.2%

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast’s Paella authentication page could be used to redirect to an arbitrary URL for authenticated users. The vulnerability allows attackers to redirect users to sites outside of one’s Opencast install, potentially facilitating phishing attacks or other security issues. This issue is fixed in Opencast 12.5 and newer.

CNA Affected

[
  {
    "vendor": "opencast",
    "product": "opencast",
    "versions": [
      {
        "version": "< 12.5",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

26.2%

Related for CVELIST:CVE-2022-41965