GHSA-vmm6-w4cf-7f3x
Authentication Bypass For Endpoints With Anonymous Access in Opencast
Quick fix
GHSA-vmm6-w4cf-7f3x — org.opencastproject:opencast-kernel: upgrade to the fixed version with the command below.
# pom.xml: bump <version>7.6</version> for org.opencastproject:opencast-kernelDetails
### Impact
Using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access.
This way, an attacker can, for example, fake a remember-me token, assume the identity of the global system administrator and request non-public content from the search service without ever providing any proper authentication.
### Patches
This problem is fixed in Opencast 7.6 and Opencast 8.1
### Workarounds
As a workaround for older, unpatched versions, disabling remember-me cookies in `etc/security/mh_default_org.xml` will mitigate the problem but will obviously also disable this feature without obvious indication. To deactivate this, remove the following line from the security configuration:
```xml <sec:remember-me … /> ```
### References
- [Remember-me cookie in the security configuration file](https://github.com/opencast/opencast/blob/161ee619382f144dc35eea211fc6b556025b98e1/etc/security/mh_default_org.xml#L335-L336)
### For more information
If you have any questions or comments about this advisory:
- Open an issue in [opencast/opencast](https://github.com/opencast/opencast/issues) - For security-relevant information, email us at security@opencast.org
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 7.6# pom.xml: bump <version>7.6</version> for org.opencastproject:opencast-kernel8.0Fixed in: 8.1# pom.xml: bump <version>8.1</version> for org.opencastproject:opencast-kernel