CVE-2020-26234
Last modified
CVE-2020-26234 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of Opencast's HTTP requests. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of Opencast's HTTP requests. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host. Disabling it can allow for man-in-the-middle attacks. This problem is fixed in Opencast 7.9 and Opencast 8.8 Please be aware that fixing the problem means that Opencast will not simply accept any self-signed certificates any longer without properly importing them. If you need those, please make sure to import them into the Java key store. Better yet, get a valid certificate.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apereo | Opencast | < 7.9 |
| Apereo | Opencast | >= 8.0, < 8.9 |
References
- https://github.com/opencast/opencast/commit/4225bf90af74557deaf8fb6b80b0705c9621acfcPatch, Third Party Advisory
- https://github.com/opencast/opencast/security/advisories/GHSA-44cw-p2hm-gpf6Third Party Advisory
- https://github.com/opencast/opencast/commit/4225bf90af74557deaf8fb6b80b0705c9621acfcPatch, Third Party Advisory
- https://github.com/opencast/opencast/security/advisories/GHSA-44cw-p2hm-gpf6Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26234?
How severe is CVE-2020-26234?
How do I fix CVE-2020-26234?
Are you affected by CVE-2020-26234?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
