BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled follow redirect at `httpclient.execute` since the software no longer has to follow it when using `finalUrl`. There are no known workarounds. We recommend upgrading to a patched version of BigBlueButton.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-48170 BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled follow redirect at `httpclient.execute` since the software no longer has to follow it when using `finalUrl`. There are no known workarounds. We recommend upgrading to a patched version of BigBlueButton.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-05T20:19:17.331Z

Reserved: 2023-09-22T14:51:42.340Z

Link: CVE-2023-43798

cve-icon Vulnrichment

Updated: 2024-08-02T19:52:11.270Z

cve-icon NVD

Status : Modified

Published: 2023-10-30T23:15:08.397

Modified: 2024-11-21T08:24:48.393

Link: CVE-2023-43798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses