PT-2020-17084 · Bigbluebutton · Bigbluebutton
Published
2020-11-26
·
Updated
2020-11-30
·
CVE-2020-29042
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BigBlueButton versions through 2.2.29
Description
An issue was discovered that allows a brute-force attack to occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
Recommendations
For BigBlueButton versions through 2.2.29, update to a version later than 2.2.29 to prevent brute-force attacks on meetings protected by an access code.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigbluebutton