BigBlueButton 代码问题漏洞(CVE-2023-33176)

admin 2023-11-29 22:57:35 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
BigBlueButton 代码问题漏洞(CVE-2023-33176)

CVE编号

CVE-2023-33176

利用情况

暂无

补丁情况

N/A

披露时间

2023-06-27
漏洞描述
BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supply a URL from which the presentation should be downloaded. This URL was being used without having been successfully validated first. An update to the `followRedirect` method in the `PresentationUrlDownloadService` has been made to validate all URLs to be used for presentation download. Two new properties `presentationDownloadSupportedProtocols` and `presentationDownloadBlockedHosts` have also been added to `bigbluebutton.properties` to allow administrators to define what protocols a URL must use and to explicitly define hosts that a presentation cannot be downloaded from. All URLs passed to `insertDocument` must conform to the requirements of the two previously mentioned properties. Additionally, these URLs must resolve to valid addresses, and these addresses must not be local or loopback addresses. There are no workarounds. Users are advised to upgrade to a patched version of BigBlueButton.
解决建议
"将组件 bigbluebutton 升级至 2.6.9 及以上版本""将组件 bigbluebutton 升级至 2.5.18 及以上版本"
参考链接
https://github.com/bigbluebutton/bigbluebutton/commit/43394dade595d0707384e48...
https://github.com/bigbluebutton/bigbluebutton/commit/b18aff32e65a47f1eb2c800...
https://github.com/bigbluebutton/bigbluebutton/pull/18045
https://github.com/bigbluebutton/bigbluebutton/pull/18052
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-3q22-...
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 bigbluebutton bigbluebutton * Up to (excluding) 2.5.18
运行在以下环境
应用 bigbluebutton bigbluebutton * From (including) 2.6.0 Up to (excluding) 2.6.9
CVSS3评分 6.5
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 无
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 无
  • 保密性 低
  • 完整性 低
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-ID 漏洞类型
CWE-918 服务端请求伪造(SSRF)
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0