Opencast users with ROLE_COURSE_ADMIN can create new users
CVE-2020-5231
What is CVE-2020-5231?
In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE_ADMIN. ROLE_COURSE_ADMIN is a non-standard role in Opencast which is referenced neither in the documentation nor in any code (except for tests) but only in the security configuration. From the name โ implying an admin for a specific course โ users would never expect that this role allows user creation. This issue is fixed in 7.6 and 8.1 which both ship a new default security configuration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
opencast < 7.6 < 7.6
opencast >= 8.0, < 8.1 < 8.0, 8.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
