Improper Authentication in Opencast - CVE-2020-5206
Published: January 29, 2020 / Updated: April 23, 2026
Opencast
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication and access non-public content.
The vulnerability exists due to improper authentication in endpoints with anonymous access when processing a remember-me cookie with an arbitrary username. A remote attacker can supply a forged remember-me cookie to bypass authentication and access non-public content.
The issue occurs only for endpoints that allow anonymous access.