Vulnerability CVE-2022-29232


Published: 2022-06-01   Modified: 2022-06-02

Description:
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a participant in a meeting on the server. BigBlueButton versions 2.3.9 and 2.4-beta-1 contain a patch for this issue. There are currently no known workarounds.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Bigbluebutton -> Bigbluebutton 

 References:
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-3fqh-p4qr-vfm9
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-beta-1
https://github.com/bigbluebutton/bigbluebutton/pull/12861
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.9

Copyright 2024, cxsecurity.com

 

Back to Top