CVE-2020-27601: Bigbluebutton
Low severity, CVSS 3.5. EPSS: 0.8% chance of exploitation in the next 30 days.
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.
Affected products
- Bigbluebutton Bigbluebutton: before 2.2.7 (fixed in 2.2.7)
Published 2022-09-29. Last modified 2026-06-17.