Use of hard-coded credentials in Opencast - CVE-2020-5222

 

Use of hard-coded credentials in Opencast - CVE-2020-5222

Published: January 29, 2020 / Updated: April 23, 2026


Vulnerability identifier: #VU127015
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5222
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to other servers.

The vulnerability exists due to use of a hard-coded cryptographic key in the remember-me token configuration in etc/security/mh_default_org.xml when validating remember-me authentication tokens. A remote attacker can reuse a compromised remember-me token from one server to gain unauthorized access to other servers.

The issue is particularly relevant in clustered deployments where multiple machines accept the same credentials.


Affected software

Opencast

How to mitigate CVE-2020-5222

Install security update from vendor's website.

Opencast - addressed in versions 7.6, 8.1

External References

Related Security Bulletins