SB2020042916 - Information disclosure in BigBlueButton
Published: April 29, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2020-12443)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an ineffective mitigation to CVE-2020-12112 (SB2020042820) in which there was an attempted fix within an NGINX configuration file, without considering that the relevant part of NGINX is case-insensitive. A remote attacker can read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence.
Remediation
Install update from vendor's website.