Path traversal in Opencast - CVE-2020-5230

 

Path traversal in Opencast - CVE-2020-5230

Published: January 29, 2020 / Updated: April 23, 2026


Vulnerability identifier: #VU127017
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5230
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write files to unintended locations.

The vulnerability exists due to improper input validation in identifier handling for media packages and elements when using identifiers in file system operations. A remote attacker can supply a crafted identifier to write files to unintended locations.


Affected software

Opencast

How to mitigate CVE-2020-5230

Install security update from vendor's website.

Opencast - addressed in versions 7.6, 8.1

External References

Related Security Bulletins