CVE-2020-27610: Bigbluebutton
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automatically set up a firewall configuration to block external access.
Affected products
- Bigbluebutton Bigbluebutton: before 2.2.28 (fixed in 2.2.28)
Published 2020-10-21. Last modified 2026-06-17.