CVE-2020-27604
Last modified
CVE-2020-27604 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bigbluebutton | Bigbluebutton | < 2.2.8 |
References
- https://www.golem.de/news/big-blue-button-das-grosse-blaue-sicherheitsrisiko-2010-151610.htmlExploit, Third Party Advisory
- https://www.golem.de/news/big-blue-button-das-grosse-blaue-sicherheitsrisiko-2010-151610.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27604?
How severe is CVE-2020-27604?
How do I fix CVE-2020-27604?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-2759Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2020-2760Vulnerability in the MySQL Server product of Oracle MySQL (c…5.5
- CVE-2020-27600HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Rou…9.8
- CVE-2020-27601In BigBlueButton before 2.2.7, lockSettingsProps.disablePriv…3.5
- CVE-2020-27602BigBlueButton before 2.2.7 does not have a protection mechan…9.8
- CVE-2020-27603BigBlueButton before 2.2.27 has an unsafe JODConverter setti…7.5
- CVE-2020-27605BigBlueButton through 2.2.28 uses Ghostscript for processing…9.8
- CVE-2020-27606BigBlueButton before 2.2.28 (or earlier) does not set the se…5.3
- CVE-2020-27607In BigBlueButton before 2.2.28 (or earlier), the client-side…6.5
- CVE-2020-27608In BigBlueButton before 2.2.28 (or earlier), uploaded presen…6.1
- CVE-2020-27609BigBlueButton through 2.2.28 records a video meeting despite…5.3
- CVE-2020-2761Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
Are you affected by CVE-2020-27604?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
