<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:31:48.451747+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-12671</id>
    <title>cnvd-2020-12671</title>
    <updated>2026-10-03T03:31:48.516889+00:00</updated>
    <content>cnvd-2020-12671</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-12671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-36449</id>
    <title>EUVD-2026-36449</title>
    <updated>2026-10-03T03:31:48.516928+00:00</updated>
    <content>EUVD-2026-36449</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-36449"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-5231</id>
    <title>fkie_cve-2020-5231</title>
    <updated>2026-10-03T03:31:48.516943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE_ADMIN. ROLE_COURSE_ADMIN is a non-standard role in Opencast which is referenced neither in the documentation nor in any code (except for tests) but only in the security configuration. From the name – implying an admin for a specific course – users would never expect that this role allows user creation. This issue is fixed in 7.6 and 8.1 which both ship a new default security configuration.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-5231"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-94qw-r73x-j7hg</id>
    <title>GHSA-94qw-r73x-j7hg — Users with ROLE_COURSE_ADMIN can create new users in Opencast</title>
    <updated>2026-10-03T03:31:48.516977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.opencastproject:opencast-kernel</p>
<p>### Impact</p>
<p>Users with the role `ROLE_COURSE_ADMIN` can use the user-utils endpoint to create new users not including the role `ROLE_ADMIN`. For example:</p>
<p>```bash
# Use the admin to create a new user with ROLE_COURSE_ADMIN using the admin user.
# We expect this to work.
% curl -i -u admin:opencast 'https://example.opencast.org/user-utils/xy.json' -X PUT \
  --data 'password=f&amp;roles=%5B%22ROLE_COURSE_ADMIN%22%5D'
HTTP/2 201</p>
<p># Use the new user to create more new users.
# We don't expüect a user with just role ROLE_COURSE_ADMIN to succeed.
# But it does work
% curl -i -u xy:f 'https://example.opencast.org/user-utils/ab.json' -X PUT \
  --data 'password=f&amp;roles=%5B%22ROLE_COURSE_ADMIN%22%5D'
HTTP/2 201
```
`ROLE_COURSE_ADMIN` is a non-standard role in Opencast which is referenced neither in the documentation nor in any code (except for tests) but only in the security configuration. From the name – implying an admin for a specific course – users would never expect that this role allows user creation.</p>
<p>### Patches</p>
<p>This issue is fixed in 7.6 and 8.1 which both ship a new default security configuration.</p>
<p>### Workarounds</p>
<p>You can fix this issue by removing all instances of `ROLE_COURSE_ADMIN` in your organization's security configuration (`etc/security/mh_default_org.xml` by default).</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>- Open an issue in [opencast/opencast](https://github.com/opencast/opencast/issues)
- For security-relevant infor…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-94qw-r73x-j7hg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-5231</id>
    <title>gsd-2020-5231</title>
    <updated>2026-10-03T03:31:48.517029+00:00</updated>
    <content>gsd-2020-5231</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-5231"/>
  </entry>
</feed>
