Vulnerability CVE-2020-27602


Published: 2022-09-29

Description:
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

 References:
https://github.com/bigbluebutton/bigbluebutton/commit/4bfd924c64da2681f4c037026021f47eb189d717
https://www.cve.org/CVERecord?id=CVE-2020-27602
https://github.com/bigbluebutton/bigbluebutton/compare/v2.2.6...v2.2.7

Copyright 2026, cxsecurity.com

 

Back to Top