PT-2022-16022 · Unknown · Bigbluebutton
Juraj Somorovsky
+2
·
Published
2022-12-17
·
Updated
2023-06-27
·
CVE-2022-23488
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BigBlueButton versions prior to 2.4-rc-6
Description
The moderators-only webcams lock setting in BigBlueButton is not enforced on the backend. This allows an attacker to subscribe to viewers' webcams, even when the lock setting is applied, by exploiting the fact that the required
streamId is sent to all users, regardless of the lock setting.Recommendations
For versions prior to 2.4-rc-6, update to version 2.4-rc-6 to resolve the issue.
As a temporary workaround, consider restricting access to the webcam feature until the update is applied.
Exploit
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bigbluebutton