Vulnerability CVE-2017-1000217


Published: 2017-11-17   Modified: 2017-11-18

Description:
Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.

Type:

CWE-74

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Opencast -> Opencast 

 References:
https://groups.google.com/a/opencast.org/forum/#!topic/security-notices/sCpt0pIPEFg

Copyright 2024, cxsecurity.com

 

Back to Top