PT-2020-17071 · Bigbluebutton · Bigbluebutton

Tiago Jacobs

·

Published

2020-11-19

·

Updated

2020-11-30

·

CVE-2020-28954

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 2.2.29
Description The issue is related to a lack of certain parameter sanitization in the web/controllers/ApiController.groovy file. This allows for the acceptance of control characters in a user name.
Recommendations For versions prior to 2.2.29, update to version 2.2.29 or later to resolve the issue. As a temporary workaround, consider restricting the input for user names to prevent the acceptance of control characters until a patch is applied.

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28954

Affected Products

Bigbluebutton