16.10
5 years ago
2 months ago
Known vulnerabilities in the org.opencastproject:base package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.opencastproject:base is a free and open source solution for automated video capture and distribution at scale. Affected versions of this package are vulnerable to Resource Injection. Opencast allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape working directories and write files to other locations. In addition, Opencast's How to fix Resource Injection? Upgrade | [8.0,8.1)[,7.6) |