CVE-2020-25820: SSRF
Published Oct 21, 2020
·Updated
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
Affected Software
1 affected component
BigBlueButton BigBlueButton<2.2.27
Remediation
Event History
Oct 21, 2020
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-25820.
2
What is the severity of CVE-2020-25820?
The severity of CVE-2020-25820 is medium with a CVSS score of 6.5.
3
What is the affected software version?
BigBlueButton versions up to and excluding 2.2.27 are affected.
4
How can remote authenticated users exploit this vulnerability?
Remote authenticated users can exploit this vulnerability by uploading an Office document with a crafted URL in an ODF xlink field, allowing them to read local files and conduct SSRF attacks.
5
Are there any available patches or fixes for this vulnerability?
Yes, BigBlueButton version 2.2.27 includes a fix for CVE-2020-25820. It is recommended to update to this version or a higher one.