Information disclosure in Opencast - CVE-2025-54380

 

Information disclosure in Opencast - CVE-2025-54380

Published: April 23, 2026


Vulnerability identifier: #VU127021
CSH Severity: Low
CVSS v4 BT: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-54380
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in mediapackage element fetching when processing a mediapackage XML file. A remote user can supply a URL of their choosing to disclose sensitive information.

The exposed information consists of the hashed global system account credentials, and exploitation requires ingest permissions.


Affected software

Opencast

How to mitigate CVE-2025-54380

Install security update from vendor's website.

Opencast - update to 17.6

External References

Related Security Bulletins