Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.opencastproject/opencast-common
  4. ›
  5. GMS-2021-145

GMS-2021-145: Opencast publishes global system account credentials

December 14, 2021

The issue was mostly mitigated before, drastically reducing the risk. See references below for more information.

Impact

Opencast before version 10.6 will try to authenticate against any external services listed in a media package when it is trying to access the files, sending the global system user’s credentials, regardless of the target being part of the Opencast cluster or not.

Previous mitigations already prevented clear text authentications for such requests (e.g. HTTP Basic authentication), but with enough malicious intent, even hashed credentials can be broken.

Patches

Opencast 10.6 will now send authentication requests only against servers which are part of the Opencast cluster, preventing external services from getting any form of authentication attempt in the first place.

Workarounds

No workaround available.

References

  • Patch fixing the issue
  • Original security notice
  • Original security mitigation

For more information

If you have any questions or comments about this advisory:

  • Open an issue in our issue tracker
  • Email us at security@opencast.org

References

  • docs.opencast.org/r/10.x/admin/
  • github.com/advisories/GHSA-hcxx-mp6g-6gr9
  • github.com/opencast/opencast/commit/776d5588f39c61eb04c03bb955416c4f77629d51
  • github.com/opencast/opencast/security/advisories/GHSA-hcxx-mp6g-6gr9

Code Behaviors & Features

Detect and mitigate GMS-2021-145 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 10.6

Fixed versions

  • 10.6

Solution

Upgrade to version 10.6 or above.

Source file

maven/org.opencastproject/opencast-common/GMS-2021-145.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:57 +0000.