Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27604

Опубликовано: 21 окт. 2020
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*
Версия до 2.2.8 (исключая)

EPSS

Процентиль: 47%
0.00237
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-116

Связанные уязвимости

github
больше 3 лет назад

BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.

EPSS

Процентиль: 47%
0.00237
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-116