GHSA-qwfv-5jwj-582h

Suggest an improvement
Source
https://github.com/advisories/GHSA-qwfv-5jwj-582h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qwfv-5jwj-582h/GHSA-qwfv-5jwj-582h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qwfv-5jwj-582h
Aliases
  • CVE-2017-1000217
Published
2022-05-14T01:06:17Z
Modified
2023-11-08T03:58:44.289757Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Opencast RCE Vulnerability
Details

Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.

Database specific
{
    "nvd_published_at": "2017-11-17T22:29:00Z",
    "cwe_ids": [
        "CWE-74"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-26T21:37:20Z"
}
References

Affected packages

Maven / org.opencastproject:base

Package

Name
org.opencastproject:base
View open source insights on deps.dev
Purl
pkg:maven/org.opencastproject/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.3

Database specific

{
    "last_known_affected_version_range": "<= 2.3.2"
}