Information disclosure in Opencast - CVE-2025-54380
Published: April 23, 2026
Opencast
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in mediapackage element fetching when processing a mediapackage XML file. A remote user can supply a URL of their choosing to disclose sensitive information.
The exposed information consists of the hashed global system account credentials, and exploitation requires ingest permissions.