BIGBLUEBUTTON has a critical path traversal vulnerability affecting versions prior to 3.0.35 and 4.0.0-beta.5, which allows attackers to perform unauthenticated arbitrary file reads. This could lead to the extraction of sensitive files and full server compromise, putting student data at risk. Immediate upgrades and the application of patches are recommended. Users are advised to switch from Etherpad to BlockNote and delete sensitive configuration files. The vulnerability has a CVSS score of 10.0, indicating maximum risk.
Critical Path Traversal Flaw in BigBlueButton Risks Student Data
CyberSIXT Evidence Panel
Primary Source
github.com
Article by CyberSIXT