CVE-2020-5206
CVE-2020-5206 is a high-severity vulnerability in Apereo Opencast with a CVSS 3.x base score of 8.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: High (CVSS 3.x base score 8.7)
- CVSS v2: 6.4
- EPSS exploit prediction: 1% (69th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Apereo Opencast
- Published:
- Last modified:
Description
In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access. This way, an attacker can, for example, fake a remember-me token, assume the identity of the global system administrator and request non-public content from the search service without ever providing any proper authentication. This problem is fixed in Opencast 7.6 and Opencast 8.1
Frequently asked questions
- What is CVE-2020-5206?
- In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access. This way, an attacker can, for example, fake a remember-me token, assume the identity of the global system administrator and request non-public content from the search service without ever providing any proper authentication. This problem is fixed in Opencast 7.6 and Opencast 8.1
- How severe is CVE-2020-5206?
- CVE-2020-5206 has a CVSS 3.x base score of 8.7, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2020-5206 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (69th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-5206?
- CVE-2020-5206 primarily affects Apereo Opencast. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2020-5206?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2020-5206 published?
- CVE-2020-5206 was published on 2020-01-30 and last updated on 2026-06-17.
References
- https://github.com/opencast/opencast/commit/b157e1fb3b35991ca7bf59f0730329fbe7ce82e8
- https://github.com/opencast/opencast/security/advisories/GHSA-vmm6-w4cf-7f3x
Affected products (2)
- cpe:2.3:a:apereo:opencast:*:*:*:*:*:*:*:*
- cpe:2.3:a:apereo:opencast:8.0:*:*:*:*:*:*:*
More vulnerabilities in Apereo Opencast
- CVE-2021-43821 — Critical (CVSS 9.9): Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6…
- CVE-2021-32623 — High (CVSS 8.1): Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to…
- CVE-2020-5230 — High (CVSS 7.7): Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be…
- CVE-2020-5229 — High (CVSS 7.7): Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm.…
- CVE-2020-5228 — High (CVSS 7.6): Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH…
- CVE-2018-16153 — High (CVSS 7.5): An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during…
All CVEs affecting Apereo Opencast →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →