PT-2022-19486 · Unknown · Bigbluebutton
Juraj Somorovsky
+2
·
Published
2022-06-01
·
Updated
2024-03-08
·
CVE-2022-29236
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BigBlueButton versions 2.2 through 2.3.17
BigBlueButton versions 2.4-rc-1 through 2.4-rc-5
Description
BigBlueButton is an open source web conferencing system. An attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant.
Recommendations
For BigBlueButton versions 2.2 through 2.3.17, update to version 2.3.18 to resolve the issue.
For BigBlueButton versions 2.4-rc-1 through 2.4-rc-5, update to version 2.4-rc-6 to resolve the issue.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigbluebutton