Advisories for Maven/Org.opencastproject/Opencast-Publication-Service-Oaipmh-Remote package

2025

Opencast still publishes global system account credentials

Opencast prior to versions 17.6 would incorrectly send the hashed global system account credentials (ie: org.opencastproject.security.digest.user and org.opencastproject.security.digest.pass) when attempting to fetch mediapackage elements included in a mediapackage XML file. A previous CVE prevented many cases where the credentials were inappropriately sent, but not all. The remainder are addressed with this patch.