PT-2022-16022 · Unknown · Bigbluebutton

Juraj Somorovsky

+2

·

Published

2022-12-17

·

Updated

2023-06-27

·

CVE-2022-23488

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 2.4-rc-6
Description The moderators-only webcams lock setting in BigBlueButton is not enforced on the backend. This allows an attacker to subscribe to viewers' webcams, even when the lock setting is applied, by exploiting the fact that the required streamId is sent to all users, regardless of the lock setting.
Recommendations For versions prior to 2.4-rc-6, update to version 2.4-rc-6 to resolve the issue. As a temporary workaround, consider restricting access to the webcam feature until the update is applied.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-23488
GHSA-J5G3-F74Q-RVFQ

Affected Products

Bigbluebutton