PT-2022-19486 · Unknown · Bigbluebutton

·

CVE-2022-29236

·

Published

2022-06-01

·

Updated

2024-03-08

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BigBlueButton versions 2.2 through 2.3.17 BigBlueButton versions 2.4-rc-1 through 2.4-rc-5
Description BigBlueButton is an open source web conferencing system. An attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant.
Recommendations For BigBlueButton versions 2.2 through 2.3.17, update to version 2.3.18 to resolve the issue. For BigBlueButton versions 2.4-rc-1 through 2.4-rc-5, update to version 2.4-rc-6 to resolve the issue.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29236
GHSA-P93G-R9GM-9V6R

Affected Products

Bigbluebutton