SCA: security update for org.opencastproject:opencast-user-interface-configuration (GHSA-hq8m-v68g-8cf8)

medium Tenable Self-Hosted Container Security Plugin ID 435153

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Opencast is a free, open-source platform to support the management of educational audio and video content.
In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config
module are insufficient, still partially allowing for attacks in very specific cases. The path is checked
without checking for the file separator. This could allow attackers access to files within another folder
which starts with the same path. This issue has been fixed in versions 17.7 and 18.1. To mitigate this
issue, check for folders that start with the same path as the ui-config folder. (CVE-2025-55202)

See Also

https://github.com/advisories/GHSA-hq8m-v68g-8cf8

Plugin Details

Severity: Medium

ID: 435153

Version: Revision 1.13

Type: Local

Family: SCA Checks

Published: 8/29/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2025-55202

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/29/2025

Vulnerability Publication Date: 8/29/2025

Reference Information

CVE: CVE-2025-55202

cwe: CWE-23