CVE-2020-29043: Infoleak
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an accountactivations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-29043.
What is the severity of CVE-2020-29043?
The severity of CVE-2020-29043 is high, with a severity value of 7.5.
What is the affected software by CVE-2020-29043?
The affected software is BigBlueButton versions up to and including 2.2.29.
How does CVE-2020-29043 work?
CVE-2020-29043 allows an attacker to create an approved user account associated with an email address that has an arbitrary domain name by exploiting the account_activations/edit?token= URI.
Are there any known references for CVE-2020-29043?
Yes, here are some references for CVE-2020-29043: [PacketStormSecurity](http://packetstormsecurity.com/files/160239/BigBlueButton-2.2.29-E-mail-Validation-Bypass.html), [CxSecurity](https://cxsecurity.com/issue/WLB-2020110211), [GitHub](https://github.com/bigbluebutton/bigbluebutton/releases).