CVE-2020-27606: Medium severity bigbluebutton vulnerability
BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27606?
CVE-2020-27606 is a vulnerability in BigBlueButton versions before 2.2.28 (or earlier) that allows remote attackers to capture the session cookie.
Is BigBlueButton affected by CVE-2020-27606?
Yes, BigBlueButton versions before 2.2.28 (or earlier) are affected by CVE-2020-27606.
What is the severity level of CVE-2020-27606?
CVE-2020-27606 has a severity level of medium with a score of 5.3.
How can remote attackers exploit CVE-2020-27606?
Remote attackers can exploit CVE-2020-27606 by intercepting the transmission of the session cookie within an HTTP session.
Is there a fix for CVE-2020-27606?
Yes, updating BigBlueButton to version 2.2.28 (or later) will fix the CVE-2020-27606 vulnerability.