Description
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
Remediation
References
https://docs.opencast.org/r/10.x/admin/#changelog
https://github.com/advisories/GHSA-hcxx-mp6g-6gr9
https://github.com/opencast/opencast/commit/776d5588f39c61eb04c03bb955416c4f77629d51
https://www.apereo.org/projects/opencast/news
Related Vulnerabilities
CVE-2023-34468 Vulnerability in maven package org.apache.nifi:nifi-dbcp-base
CVE-2022-22984 Vulnerability in npm package snyk-mvn-plugin
CVE-2018-20676 Vulnerability in maven package org.webjars.bower:bootstrap-sass
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.13
CVE-2022-31142 Vulnerability in npm package fastify-bearer-auth