Use of hard-coded credentials in Opencast - CVE-2020-5222
Published: January 29, 2020 / Updated: April 23, 2026
Opencast
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to other servers.
The vulnerability exists due to use of a hard-coded cryptographic key in the remember-me token configuration in etc/security/mh_default_org.xml when validating remember-me authentication tokens. A remote attacker can reuse a compromised remember-me token from one server to gain unauthorized access to other servers.
The issue is particularly relevant in clustered deployments where multiple machines accept the same credentials.