CVE-2020-27612: Infoleak
Published Oct 21, 2020
·Updated
Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information leak to users in a room, or an information leak to outsiders if any user publishes a screenshot of a browser window.
Affected Software
1 affected component
BigBlueButton BigBlueButton<=2.2.28
Event History
Oct 21, 2020
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-27612.
2
What is the severity of the CVE-2020-27612 vulnerability?
The severity of the CVE-2020-27612 vulnerability is medium with a severity value of 4.3.
3
What is the affected software version for CVE-2020-27612?
The affected software version for CVE-2020-27612 is BigBlueButton through 2.2.28.
4
What is the potential impact of CVE-2020-27612?
The potential impact of CVE-2020-27612 is an unintended information leak to users in a room or an information leak to outsiders if any user publishes a screenshot.
5
Is there a fix available for CVE-2020-27612?
Yes, there is a fix available. Please refer to the official documentation for BigBlueButton for more information.