{"id":"CVE-2020-5230","details":"Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape working directories and write files to other locations. In addition, Opencast's Id.toString(…) vs Id.compact(…) behavior, the latter trying to mitigate some of the file system problems, can cause errors due to identifier mismatch since an identifier may unintentionally change. This issue is fixed in Opencast 7.6 and 8.1.","aliases":["GHSA-w29m-fjp4-qhmq"],"modified":"2026-07-09T01:25:20.485526Z","published":"2020-01-30T21:15:15.167Z","references":[{"type":"ADVISORY","url":"https://github.com/opencast/opencast/security/advisories/GHSA-w29m-fjp4-qhmq"},{"type":"FIX","url":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencast/opencast","events":[{"introduced":"0"},{"fixed":"6241ba154a6b364fea1928e52f8bf2a432934dc8"},{"introduced":"5bb6a93a43a7f7c47f789e46e4018c80b8c54c8b"},{"last_affected":"5bb6a93a43a7f7c47f789e46e4018c80b8c54c8b"},{"fixed":"bbb473f34ab95497d6c432c81285efb0c739f317"}],"database_specific":{"cpe":["cpe:2.3:a:apereo:opencast:*:*:*:*:*:*:*:*","cpe:2.3:a:apereo:opencast:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"7.6"},{"introduced":"8.0"},{"last_affected":"8.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["8.0"],"database_specific":{"vanir_signatures_modified":"2026-07-09T01:25:20Z","vanir_signatures":[{"id":"CVE-2020-5230-0b80ab61","signature_type":"Function","signature_version":"v1","source":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317","target":{"file":"modules/common/src/main/java/org/opencastproject/mediapackage/identifier/IdImpl.java","function":"IdImpl"},"deprecated":false,"digest":{"function_hash":"216190859915552726671707505792069809036","length":51}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317","target":{"file":"modules/ingest-service-impl/src/main/java/org/opencastproject/ingest/endpoint/IngestRestService.java"},"deprecated":false,"digest":{"line_hashes":["73158565843399564860828732441292758002","226851973213465726000406202140222435355","142530729630901758211176474010030465041","225589291142681575013023594369129510004","21457923428656999645782057042364804297","161556562876718430804090222177043821458","72402404511538037481975210434537328138","269741042779162491642504432386112334079"],"threshold":0.9},"id":"CVE-2020-5230-3430a2ea"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317","target":{"file":"modules/ingest-service-impl/src/main/java/org/opencastproject/ingest/endpoint/IngestRestService.java","function":"addMediaPackage"},"deprecated":false,"digest":{"function_hash":"146697880931529684172930331714821880134","length":4364},"id":"CVE-2020-5230-43a6cc77"},{"digest":{"line_hashes":["133596038857241399085537718849488557237","207770760516590117897371367554099375719","129404561395784555879427726795327538628","305201457301659893137373711172825226109","317798760297441477962677468115773845707","50075764870067004774974241489591083259","3084347032606933625036131438307832692","95791829242473518132972406393860438328","318832727447354205616868587621112000565","57929422994237807717264742445782446299","181230684369697288866623801503337301054","65303256150263420827622569286992724657"],"threshold":0.9},"id":"CVE-2020-5230-75faba8d","signature_type":"Line","signature_version":"v1","source":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317","target":{"file":"modules/common/src/main/java/org/opencastproject/mediapackage/identifier/IdImpl.java"},"deprecated":false},{"id":"CVE-2020-5230-8337bb50","signature_type":"Function","signature_version":"v1","source":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317","target":{"file":"modules/common/src/main/java/org/opencastproject/mediapackage/identifier/IdImpl.java","function":"compact"},"deprecated":false,"digest":{"length":87,"function_hash":"162570788934587347791102363068513625885"}},{"signature_version":"v1","source":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317","target":{"file":"modules/common/src/main/java/org/opencastproject/mediapackage/identifier/Id.java"},"deprecated":false,"digest":{"line_hashes":["69797736154236882272652478800920919494","319804724600842031130085551402219661415","334478982509335683475935112755839207254"],"threshold":0.9},"id":"CVE-2020-5230-86345984","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5230.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}