Vulnerability Description
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bigbluebutton | Bigbluebutton | < 2.2.7 |
Related Weaknesses (CWE)
References
- https://github.com/bigbluebutton/bigbluebutton/commit/7dcdfb191373684bafa7b11cddPatchThird Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/compare/v2.2.6...v2.2.7Release NotesThird Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/commit/7dcdfb191373684bafa7b11cddPatchThird Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/compare/v2.2.6...v2.2.7Release NotesThird Party Advisory
FAQ
What is CVE-2020-27601?
CVE-2020-27601 is a vulnerability with a CVSS score of 3.5 (LOW). In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.
How severe is CVE-2020-27601?
CVE-2020-27601 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27601?
Check the references section above for vendor advisories and patch information. Affected products include: Bigbluebutton Bigbluebutton.