CVE-2020-27610: High severity bigbluebutton vulnerability
The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automatically set up a firewall configuration to block external access.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this BigBlueButton vulnerability?
The vulnerability ID for this BigBlueButton vulnerability is CVE-2020-27610.
What is the title of this BigBlueButton vulnerability?
The title of this BigBlueButton vulnerability is 'The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces'.
What is the severity of CVE-2020-27610?
CVE-2020-27610 has a severity rating of high with a value of 7.5.
What software is affected by CVE-2020-27610?
The BigBlueButton software versions up to and excluding 2.2.28 are affected by CVE-2020-27610.
How can I fix the CVE-2020-27610 vulnerability in BigBlueButton?
To fix the CVE-2020-27610 vulnerability in BigBlueButton, update to version 2.2.28 or higher and configure a firewall to block external access.