Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-33176

Опубликовано: 26 июн. 2023
Источник: nvd
CVSS3: 4.8
CVSS3: 6.5
EPSS Низкий

Описание

BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an insertDocument API request the user is able to supply a URL from which the presentation should be downloaded. This URL was being used without having been successfully validated first. An update to the followRedirect method in the PresentationUrlDownloadService has been made to validate all URLs to be used for presentation download. Two new properties presentationDownloadSupportedProtocols and presentationDownloadBlockedHosts have also been added to bigbluebutton.properties to allow administrators to define what protocols a URL must use and to explicitly define hosts that a presentation cannot be downloaded from. All URLs passed to insertDocument must conform to the requirements of the two previously mentioned properties. Additionally, these URLs must resolve to valid addresses,

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*
Версия до 2.5.18 (исключая)
cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*
Версия от 2.6.0 (включая) до 2.6.9 (исключая)

EPSS

Процентиль: 26%
0.0009
Низкий

4.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-918

EPSS

Процентиль: 26%
0.0009
Низкий

4.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-918