Lucene search

K
osvGoogleOSV:CVE-2021-32623
HistoryJun 16, 2021 - 12:15 a.m.

CVE-2021-32623

2021-06-1600:15:07
Google
osv.dev
4
opencast
vulnerable
billion laughs attack
denial of service
http request
ingest privileges

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

31.9%

Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to 9.6 are vulnerable to the billion laughs attack, which allows an attacker to easily execute a (seemingly permanent) denial of service attack, essentially taking down Opencast using a single HTTP request. To exploit this, users need to have ingest privileges, limiting the group of potential attackers The problem has been fixed in Opencast 9.6. There is no known workaround for this issue.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

31.9%