PT-2026-94348 · Opencast · Opencast
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Opencast versions prior to 19.7
Opencast versions prior to 20.2
Description
The default security configuration in etc/security/mh default org.xml accepts a client-selected session identifier from the
;jsessionid= URL path parameter and fails to replace it upon user authentication. An unauthenticated attacker can provide a crafted link to a user without an active session cookie and, once the user authenticates, reuse that identifier to hijack the authenticated session. This can lead to unauthorized access to user data and actions, or full administrative account takeover if the victim has administrator privileges.Recommendations
Update to version 19.7 or later.
Update to version 20.2 or later.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencast