CVE-2020-27611: High severity bigbluebutton vulnerability
Published Oct 21, 2020
·Updated
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
Affected Software
1 affected component
BigBlueButton BigBlueButton<=2.2.28
Remediation
Event History
Oct 21, 2020
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
Description
Frequently Asked Questions
1
What is CVE-2020-27611?
CVE-2020-27611 is a vulnerability in BigBlueButton through 2.2.28 that uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
2
What is the severity of CVE-2020-27611?
The severity of CVE-2020-27611 is high, with a severity value of 7.3.
3
How does CVE-2020-27611 affect BigBlueButton?
CVE-2020-27611 affects BigBlueButton versions up to and including 2.2.28.
4
How do I fix CVE-2020-27611?
To fix CVE-2020-27611, it is recommended to update to a version of BigBlueButton that is not affected by the vulnerability.
5
Where can I find more information about CVE-2020-27611?
More information about CVE-2020-27611 can be found in the official BigBlueButton documentation and the related GitHub commit.