PT-2020-17084 · Bigbluebutton · Bigbluebutton

Published

2020-11-26

·

Updated

2020-11-30

·

CVE-2020-29042

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions through 2.2.29
Description An issue was discovered that allows a brute-force attack to occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
Recommendations For BigBlueButton versions through 2.2.29, update to a version later than 2.2.29 to prevent brute-force attacks on meetings protected by an access code.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29042

Affected Products

Bigbluebutton