First published: Wed Oct 21 2020(Updated: )
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bigbluebutton Bigbluebutton | <2.2.27 |
https://github.com/bigbluebutton/bigbluebutton/commit/71fe1eac1e5bd73a2cd44bd79c001086b250e435
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2020-25820.
The severity of CVE-2020-25820 is medium with a CVSS score of 6.5.
BigBlueButton versions up to and excluding 2.2.27 are affected.
Remote authenticated users can exploit this vulnerability by uploading an Office document with a crafted URL in an ODF xlink field, allowing them to read local files and conduct SSRF attacks.
Yes, BigBlueButton version 2.2.27 includes a fix for CVE-2020-25820. It is recommended to update to this version or a higher one.