{"id":"CVE-2018-16153","aliases":["GHSA-hcxx-mp6g-6gr9"],"url":"https://o3.security/vulnerability/CVE-2018-16153","summary":"Opencast publishes global system account credentials","details":"An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.","published":"2023-12-12T17:15:07.517Z","modified":"2026-07-09T01:25:42.534487Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.opencastproject:opencast-common","fixedVersion":"10.6"}],"fix":{"url":"https://github.com/opencast/opencast/commit/776d5588f39c61eb04c03bb955416c4f77629d51","label":"opencast/opencast@776d558"},"references":[{"type":"ADVISORY","url":"https://docs.opencast.org/r/10.x/admin/#changelog"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hcxx-mp6g-6gr9"},{"type":"ADVISORY","url":"https://www.apereo.org/projects/opencast/news"},{"type":"FIX","url":"https://github.com/opencast/opencast/commit/776d5588f39c61eb04c03bb955416c4f77629d51"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:25:42.534487Z"}}