XML Entity Expansion in Opencast - CVE-2021-32623
Published: June 15, 2021 / Updated: April 23, 2026
Opencast
Apereo Foundation
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the XML parser when processing a crafted XML request. A remote user can send a specially crafted XML document to cause a denial of service.
Exploitation requires ingest privileges, and a single HTTP request can trigger the issue.