CVE-2020-26163: High severity bigbluebutton vulnerability
Published Sep 30, 2020
·Updated
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
Affected Software
1 affected component
BigBlueButton Greenlight<2.5.6
Remediation
Patch Available
Event History
Sep 30, 2020
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26163?
CVE-2020-26163 is a vulnerability in BigBlueButton Greenlight before version 2.5.6 that allows HTTP header (Host and Origin) attacks.
2
How severe is CVE-2020-26163?
CVE-2020-26163 has a severity rating of 8.8 (high).
3
How can CVE-2020-26163 be exploited?
CVE-2020-26163 can be exploited through HTTP header attacks, specifically Host and Origin header attacks.
4
What is the impact of CVE-2020-26163?
CVE-2020-26163 can result in an Account Takeover if a victim follows a spoofed password-reset link.
5
How can I fix CVE-2020-26163?
CVE-2020-26163 can be fixed by updating to BigBlueButton Greenlight version 2.5.6 or later.