First published: Wed Oct 21 2020(Updated: )
BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bigbluebutton Bigbluebutton | <2.2.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27606 is a vulnerability in BigBlueButton versions before 2.2.28 (or earlier) that allows remote attackers to capture the session cookie.
Yes, BigBlueButton versions before 2.2.28 (or earlier) are affected by CVE-2020-27606.
CVE-2020-27606 has a severity level of medium with a score of 5.3.
Remote attackers can exploit CVE-2020-27606 by intercepting the transmission of the session cookie within an HTTP session.
Yes, updating BigBlueButton to version 2.2.28 (or later) will fix the CVE-2020-27606 vulnerability.