BigBlueButton 2.7.8 released!

181 views
Skip to first unread message

Anton Georgiev

unread,
May 16, 2024, 8:44:35 AM5/16/24
to BigBlueButton-dev
We are pleased to announce BigBlueButton 2.7.8.

This iteration of BigBlueButton 2.7 contains a couple of security patches. Several client fixes and dependency updates were also included.

Important: We removed support for POST requests on join endpoint and also Content-Type headers are now required

In BigBlueButton 2.6.18/2.7.8 POST requests are no longer allowed for the join endpoint. To ensure they are validated properly, a Content-Type header must also be provided for POST requests that contain data in the request body. Endpoints now support a limited set of content types that includes text/xml, application/xml, application/x-www-form-url-encoded, and multipart/form-data. By default each endpoint only supports application/x-www-form-urlencoded and multipart/form-data, but individual endpoints can override this and define their own set of supported content types. The create endpoint supports all of the four previously listed content types while insertDocument supports only text/xml and application/xml. Any requests with a content type that differs from the set supported by the target endpoint will be rejected with a new unsupportedContentType error.

Link to installation command / instructions/ features : https://docs.bigbluebutton.org/2.7/new-features

The full release notes are here
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.7.8

To try out 2.7.8, visit
https://test27.bigbluebutton.org/

If you want to report any potential security issues with BigBlueButton, please check https://github.com/bigbluebutton/bigbluebutton/security/policy#reporting-a-vulnerability

As always, we welcome feedback on this latest update.

Anton and team

Daniel Schröter

unread,
Jun 9, 2024, 1:55:56 AM6/9/24
to BigBlueButton-dev
When you are going to release the security advisories you mentioned in release notes after May 31th?

Daniel Schröter

unread,
Jun 16, 2024, 3:30:21 AM6/16/24
to BigBlueButton-dev
Nobody has an ETA when the new security advisories are available?

Anton Georgiev

unread,
Jun 20, 2024, 2:40:03 PM6/20/24
to BigBlueButton-dev
Expect them some time next week.
Reply all
Reply to author
Forward
0 new messages