Vulnerabilities > CVE-2020-29042 - Improper Restriction of Excessive Authentication Attempts vulnerability in Bigbluebutton
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://packetstormsecurity.com/files/160238/BigBlueButton-2.2.29-Brute-Force.html
- http://packetstormsecurity.com/files/160238/BigBlueButton-2.2.29-Brute-Force.html
- https://cxsecurity.com/issue/WLB-2020110210
- https://cxsecurity.com/issue/WLB-2020110210
- https://github.com/bigbluebutton/bigbluebutton/releases
- https://github.com/bigbluebutton/bigbluebutton/releases