Authentication Bypass by Spoofing in Opencast - CVE-2021-43807
Published: December 14, 2021 / Updated: April 23, 2026
Opencast
Apereo Foundation
Description
The vulnerability allows a remote user to bypass request method restrictions and perform unauthorized state-changing actions.
The vulnerability exists due to authentication bypass by spoofing in the HTTP method handling logic when processing requests with a URL parameter that overrides the HTTP method. A remote user can craft a link or form that changes the assumed HTTP method to bypass request restrictions and perform unauthorized state-changing actions.
User interaction is required, such as an authenticated administrator clicking a crafted link or submitting a crafted form.