Improper access control in Opencast - CVE-2020-5228
Published: January 29, 2020 / Updated: April 23, 2026
Opencast
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose media and metadata.
The vulnerability exists due to improper access control in the OAI-PMH endpoint when handling unauthenticated requests. A remote attacker can access published media and metadata to disclose media and metadata.
OAI-PMH is part of the default workflow and is activated by default.