{"id":"GHSA-w29m-fjp4-qhmq","summary":"Unsafe Identifiers in Opencast","details":"### Impact\n\nOpencast allows almost arbitrary identifiers for media packages and\nelements to be used. This can be problematic for operation and security\nsince such identifiers are sometimes used for file system operations\nwhich may lead to an attacker being able to escape working directories and\nwrite files to other locations.\n\nIn addition, Opencast's Id.toString(…) vs Id.compact(…) behavior,\nthe latter trying to mitigate some of the file system problems, can\ncause errors due to identifier mismatch since an identifier may\nunintentionally change.\n\n### Patches\n\nThis issue is fixed in Opencast 7.6 and 8.1.\n\n### Workarounds\n\nThere is no workaround for this.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [opencast/opencast](https://github.com/opencast/opencast/issues)\n- For security-relevant information, email us at security@opencast.org","aliases":["CVE-2020-5230"],"modified":"2026-01-30T01:37:28.755305Z","published":"2020-01-30T21:21:50Z","related":["CVE-2020-5230"],"database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-01-30T20:35:35Z","nvd_published_at":null,"cwe_ids":["CWE-99"]},"references":[{"type":"WEB","url":"https://github.com/opencast/opencast/security/advisories/GHSA-w29m-fjp4-qhmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5230"},{"type":"WEB","url":"https://github.com/opencast/opencast/commit/bbb473f34ab95497d6c432c81285efb0c739f317"}],"affected":[{"package":{"name":"org.opencastproject:base","ecosystem":"Maven","purl":"pkg:maven/org.opencastproject/base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.6"}]}],"versions":["6.6","7.2","7.3","7.4","7.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-w29m-fjp4-qhmq/GHSA-w29m-fjp4-qhmq.json"}},{"package":{"name":"org.opencastproject:base","ecosystem":"Maven","purl":"pkg:maven/org.opencastproject/base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0"},{"fixed":"8.1"}]}],"versions":["8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-w29m-fjp4-qhmq/GHSA-w29m-fjp4-qhmq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}