📦 Opencast

by Apereo

🔍 What is Opencast?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-43821

CRITICAL CVSS 9.9 Dec 14, 2021

Opencast versions before 9.10 and 10.6 allow attackers with media ingestion privileges to include local file URLs in media packages, exposing sensitive files from the host system through the web inter...

CVE-2021-32623

HIGH CVSS 8.1 Jun 16, 2021

CVE-2021-32623 is a billion laughs attack vulnerability in Opencast that allows authenticated users with ingest privileges to execute a permanent denial of service attack using a single HTTP request. ...

CVE-2025-61788

MEDIUM CVSS 5.4 Oct 8, 2025

Opencast versions before 17.8 and 18.2 have a stored cross-site scripting (XSS) vulnerability where user-supplied metadata (like titles and descriptions) is rendered without proper sanitization in the...

CVE-2025-61906

MEDIUM CVSS 4.3 Oct 8, 2025

Opencast's editor may publish videos without user notification when users with write access click 'Save & Publish' then select 'Save' instead. This could accidentally expose internal media not intende...

CVE-2025-54380

MEDIUM CVSS 6.5 Jul 26, 2025

Opencast versions before 17.6 incorrectly send hashed global system account credentials to attacker-controlled URLs when fetching mediapackage elements. This allows authenticated users with ingest per...