CVE-2020-5222: Use of Hard-coded Credentials
(updated )
Opencast enables a remember-me
cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me
token for one server can get access to all servers which allow log-in using the same credentials without ever needing the credentials.
References
Detect and mitigate CVE-2020-5222 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →