TL;DR
BigBlueButton contains a critical path traversal vulnerability within the Etherpad integration. Attackers can perform an unauthenticated arbitrary file read to extract sensitive system files. Developers released patches and strongly recommend immediate upgrades to secure virtual classrooms.
Why It Matters
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. It supports real-time sharing of audio, video, slides, chat, and screens. Thousands of educational institutions globally rely on it. A CVSS 10.0 severity score indicates maximum risk. An attacker could extract critical system files using this unauthenticated arbitrary file read. This unauthorized access could lead to full server compromise. Therefore, ignoring this flaw puts student data at immense risk.
How the Attack Works
The vulnerability exists within the Etherpad shared-notes integration. An attacker sends a crafted network request containing path traversal sequences. The server processes this request without proper validation. Consequently, the application reads and returns external files. Hackers can grab sensitive configurations directly from the host system. This unauthenticated arbitrary file read exploit requires no user interaction or specialized credentials.
Affected Versions
This critical defect affects multiple release branches. BigBlueButton versions prior to 3.0.35 contain the vulnerability. Additionally, versions before 4.0.0-beta.5 remain exposed. The vendor has not confirmed active exploitation in the wild.
Patch and Mitigation Steps
Administrators must update to version 3.0.35 or 4.0.0-beta.5 immediately. Alternatively, users can manually apply the security patch. Developers advise switching from Etherpad to BlockNote. You must delete the configuration file to remove the entry point completely. Furthermore, the advisory states, “we encourage administrators to proactively rotate the API secret.” Review the official GitHub security advisory for complete instructions.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.