-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.opencastproject:opencast-common | maven | < 9.10 | 9.10 |
The vulnerability stems from the use of an outdated Apache CXF dependency (version <3.4.3) that allowed HTTP method spoofing via the '_method' parameter. The patches (commits 59cb673 and 8f8271e) only update the CXF version in 'pom.xml' files, indicating the vulnerability resided in CXF's internal request handling logic, not in Opencast's own code. No specific functions within the 'opencast-common' package were modified or identified as directly implementing the vulnerable behavior. The issue was mitigated by updating the library dependency rather than modifying application code.
Ongoing coverage of React2Shell