{"id":"CVE-2020-5206","details":"In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access. This way, an attacker can, for example, fake a remember-me token, assume the identity of the global system administrator and request non-public content from the search service without ever providing any proper authentication. This problem is fixed in Opencast 7.6 and Opencast 8.1","aliases":["GHSA-vmm6-w4cf-7f3x"],"modified":"2026-07-09T01:07:53.588737Z","published":"2020-01-30T22:15:10.093Z","references":[{"type":"ADVISORY","url":"https://github.com/opencast/opencast/security/advisories/GHSA-vmm6-w4cf-7f3x"},{"type":"FIX","url":"https://github.com/opencast/opencast/commit/b157e1fb3b35991ca7bf59f0730329fbe7ce82e8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencast/opencast","events":[{"introduced":"0"},{"fixed":"6241ba154a6b364fea1928e52f8bf2a432934dc8"},{"introduced":"5bb6a93a43a7f7c47f789e46e4018c80b8c54c8b"},{"last_affected":"5bb6a93a43a7f7c47f789e46e4018c80b8c54c8b"},{"fixed":"b157e1fb3b35991ca7bf59f0730329fbe7ce82e8"}],"database_specific":{"cpe":["cpe:2.3:a:apereo:opencast:*:*:*:*:*:*:*:*","cpe:2.3:a:apereo:opencast:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"7.6"},{"introduced":"8.0"},{"last_affected":"8.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5206.json","vanir_signatures_modified":"2026-07-09T01:07:53Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/opencast/opencast/commit/b157e1fb3b35991ca7bf59f0730329fbe7ce82e8","target":{"file":"modules/kernel/src/main/java/org/opencastproject/kernel/security/SecurityServiceSpringImpl.java","function":"getUser"},"deprecated":false,"digest":{"function_hash":"167346135946564669046519915409421511479","length":1295},"id":"CVE-2020-5206-512cd126"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["75734271569501890742707772433482178339","9449146567902022179387120400375231962","26497533256406873041303374309956159704","297316715959913770141208720028423518536","297606026605268180059405808325019465599","243848335991179446238398700925076172114","314978509694484350818193829998104722191","273497479687732357750155179060993310467","93061623914477109868448453301859978307","54237984380871022123563447646474255136","56758462960864214513846614017296084741","68713570741423335150937093381461604945","248133498536070940049255215164087235288","71363555222591940687754051745369406245","198617838609609575598291077525213931328","3983025312276577579023255530653434805","45953953377927039865200941334146225818","231150002775214218949467454066609038781","162997854360279914929087427543946226373","257579352272766048081902690901959992461","91585432208515058336699489430221841564","56845993912443392280357661555440288217","144535471280545180173825053350102738412","328874135712492332490705915419693968116","68416579223047458720870837242649533353","33895084022467220835259949710458856719"]},"id":"CVE-2020-5206-cb4ea6e9","signature_type":"Line","signature_version":"v1","source":"https://github.com/opencast/opencast/commit/b157e1fb3b35991ca7bf59f0730329fbe7ce82e8","target":{"file":"modules/kernel/src/main/java/org/opencastproject/kernel/security/SecurityServiceSpringImpl.java"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}