CVE-2024-52797
Last modified
CVE-2024-52797 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch integration may generate syntactically invalid Elasticsearch queries in relation to previously acceptable search queries. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch integration may generate syntactically invalid Elasticsearch queries in relation to previously acceptable search queries. From Opencast version 11.4 and newer, Elasticsearch queries are retried a configurable number of times in the case of error to handle temporary losses of connection to Elasticsearch. These invalid queries would fail, causing the retry mechanism to begin requerying with the same syntactically invalid query immediately, in an infinite loop. This causes a massive increase in log size which can in some cases cause a denial of service due to disk exhaustion. Opencast 13.10 and Opencast 14.3 contain patches which address the base issue, with Opencast 16.7 containing changes which harmonize the search behaviour between the admin UI and external API. Users are strongly recommended to upgrade as soon as possible if running versions prior to 13.10 or 14.3. While the relevant endpoints require (by default) `ROLE_ADMIN` or `ROLE_API_SERIES_VIEW`, the problem queries are otherwise innocuous. This issue could be easily triggered by normal administrative work on an affected Opencast system. Those who run a version newer than 13.10 and 14.3 and see different results when searching in their admin UI vs your external API or LMS, may resolve the issue by upgrading to 16.7. No known workarounds for the vulnerability are available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apereo | Opencast | >= 11.4, < 13.10 |
| Apereo | Opencast | >= 14.0, < 14.3 |
| Apereo | Opencast | >= 15.0, < 16.7 |
References
- https://github.com/opencast/opencast/pull/5033Issue Tracking, Patch
- https://github.com/opencast/opencast/pull/5150Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-52797?
How severe is CVE-2024-52797?
How do I fix CVE-2024-52797?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5279A vulnerability was found in Qiwen Netdisk up to 1.4.0. It h…5.3
- CVE-2024-52791Matrix Media Repo (MMR) is a highly configurable multi-homes…7.5
- CVE-2024-52792LDAP Account Manager (LAM) is a php webfrontend for managing…6.5
- CVE-2024-52793The Deno Standard Library provides APIs for Deno and the Web…5.1
- CVE-2024-52794Discourse is an open source platform for community discussio…6.1
- CVE-2024-52796Password Pusher, an open source application to communicate s…5.3
- CVE-2024-52798path-to-regexp turns path strings into a regular expressions…7.7
- CVE-2024-52799Argo Workflows Chart is used to set up argo and its needed d…8.2
- CVE-2024-5280The wp-affiliate-platform WordPress plugin before 6.5.1 does…4.7
- CVE-2024-52800veraPDF is an open source PDF/A validation library. Executin…2.3
- CVE-2024-52801sftpgo is a full-featured and highly configurable event-driv…5.3
- CVE-2024-52802RIOT is an operating system for internet of things (IoT) dev…7.5
Are you affected by CVE-2024-52797?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
