CVE-2020-27609: Medium severity bigbluebutton vulnerability
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27609?
CVE-2020-27609 is a vulnerability in BigBlueButton versions up to and including 2.2.28 that allows the recording of video meetings despite the deactivation of video recording in the user interface.
What is the severity of CVE-2020-27609?
The severity of CVE-2020-27609 is medium with a CVSS score of 5.3.
How does CVE-2020-27609 affect BigBlueButton?
CVE-2020-27609 affects BigBlueButton versions up to and including 2.2.28 by enabling the recording of video meetings even when video recording is deactivated.
How can I fix CVE-2020-27609?
To fix CVE-2020-27609, it is recommended to update BigBlueButton to a version beyond 2.2.28 and ensure that video recording is properly deactivated.
Where can I find more information about CVE-2020-27609?
More information about CVE-2020-27609 can be found in the references: [Reference 1](https://docs.bigbluebutton.org/admin/privacy.html) and [Reference 2](https://www.golem.de/news/big-blue-button-das-grosse-blaue-sicherheitsrisiko-2010-151610.html).