Sandbox vulnerability in BigBlueButton by BigBlueButton Inc.
CVE-2020-27605
9.8CRITICAL
What is CVE-2020-27605?
BigBlueButton versions up to 2.2.28 utilize Ghostscript for processing uploaded EPS documents, which exposes the system to potential attacks due to weaknesses in the sandbox environment. This vulnerability could allow unauthorized actions that compromise the integrity and security of the application, making it crucial for users and administrators to be aware of these risks and apply necessary mitigations.
