Path Traversal Vulnerability in Opencast Educational Content Platform
CVE-2025-55202
2.7LOW
What is CVE-2025-55202?
Opencast, an open-source educational audio and video content management platform, has a significant path traversal vulnerability affecting versions 18.0 and earlier than 17.7 in its UI config module. The vulnerability arises from inadequate protections, allowing attackers to exploit file path checks that do not adequately verify file separators. This flaw could potentially grant unauthorized access to files in directories that share similar starting paths. Users are strongly advised to upgrade to versions 17.7 or 18.1 or to implement mitigations that involve inspecting folder names that closely resemble the ui-config folder path to enhance security.
Affected Version(s)
opencast < 17.7 < 17.7
opencast = 18.0 = 18.0