CVE-2020-27608: XSS
Published Oct 21, 2020
·Updated
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.
Affected Software
1 affected component
BigBlueButton BigBlueButton<2.2.28
Event History
Oct 21, 2020
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
Description
Frequently Asked Questions
1
What is CVE-2020-27608?
CVE-2020-27608 is a vulnerability in BigBlueButton before version 2.2.28 that allows for XSS attacks by sending uploaded presentations to clients without a Content-Type header.
2
How severe is CVE-2020-27608?
CVE-2020-27608 has a severity value of 6.1, which is considered medium.
3
How does CVE-2020-27608 affect BigBlueButton?
CVE-2020-27608 affects BigBlueButton versions up to and including 2.2.28.
4
What is the CWE classification for CVE-2020-27608?
CVE-2020-27608 is classified as CWE-79, which is a Cross-Site Scripting (XSS) vulnerability.
5
Is there a fix available for CVE-2020-27608?
Yes, updating to BigBlueButton version 2.2.29 or later will fix the vulnerability.