First published: Wed Oct 21 2020(Updated: )
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bigbluebutton Bigbluebutton | <2.2.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27608 is a vulnerability in BigBlueButton before version 2.2.28 that allows for XSS attacks by sending uploaded presentations to clients without a Content-Type header.
CVE-2020-27608 has a severity value of 6.1, which is considered medium.
CVE-2020-27608 affects BigBlueButton versions up to and including 2.2.28.
CVE-2020-27608 is classified as CWE-79, which is a Cross-Site Scripting (XSS) vulnerability.
Yes, updating to BigBlueButton version 2.2.29 or later will fix the vulnerability.