HIGH
An issue was discovered in BigBlueButton through 2.2.29
Published Nov 26, 2020
7.5
HIGHCVSS 3.1
EPSS 1.45%
Description
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.
Affected products
No data.
- ≤ 2.2.29
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://packetstormsecurity.com/files/160239/BigBlueButton-2.2.29-E-mail-Validation-Bypass.html x_refsource_MISCThird Party Advisory
- https://cxsecurity.com/issue/WLB-2020110211 x_refsource_MISCExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21425 Advisory
- https://github.com/bigbluebutton/bigbluebutton/releases x_refsource_MISCRelease NotesThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/160239/BigBlueButton-2.2.29-E-mail-Validation-Bypass.html | x_refsource_MISCThird Party Advisory | |
| https://cxsecurity.com/issue/WLB-2020110211 | x_refsource_MISCExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21425 | Advisory | |
| https://github.com/bigbluebutton/bigbluebutton/releases | x_refsource_MISCRelease NotesThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 26, 2020
Updated Aug 4, 2024
Reserved Nov 24, 2020
Link CVE-2020-29043
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-21425 Assigner mitre
Published Nov 26, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-21425