Insufficiently protected credentials in Opencast - CVE-2018-16153
Published: December 14, 2021 / Updated: April 23, 2026
Opencast
Apereo Foundation
Description
The vulnerability allows a remote attacker to obtain global system account credentials.
The vulnerability exists due to insufficiently protected credentials in media package external service authentication handling when accessing files referenced by user-supplied media packages. A remote attacker can include an external service in a media package to obtain global system account credentials.
Previous protections reduced exposure of cleartext authentication, but authentication attempts could still disclose credentials in a form that may be recoverable.