First published: Mon Oct 30 2023(Updated: )
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton 2.6.0-beta.2 contains a patch. There are no known workarounds.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bigbluebutton Bigbluebutton | <=2.5.18 | |
Bigbluebutton Bigbluebutton | =2.6.0-alpha1 | |
Bigbluebutton Bigbluebutton | =2.6.0-alpha2 | |
Bigbluebutton Bigbluebutton | =2.6.0-alpha3 | |
Bigbluebutton Bigbluebutton | =2.6.0-alpha4 | |
Bigbluebutton Bigbluebutton | =2.6.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42803 is the identifier for the BigBlueButton Unrestricted File Upload vulnerability.
CVE-2023-42803 has a severity rating of 8.8 (high).
The vulnerability occurs when the insertDocument API call in BigBlueButton does not properly validate the file extension before saving the file, allowing an attacker to upload malicious files.
The vulnerability affects BigBlueButton versions up to and including 2.5.18.
To fix CVE-2023-42803, you should update to a version of BigBlueButton that is not affected by the vulnerability.