PT-2022-26187 · Unknown · Bigbluebutton
Juraj Somorovsky
+2
·
Published
2022-12-16
·
Updated
2022-12-20
·
CVE-2022-41963
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BigBlueButton versions prior to 2.4.3
Description
BigBlueButton is an open source web conferencing system. The system contains a whiteboard grace period to handle delayed messages, but this period can be exploited by attackers to perform actions in the few seconds after their access is revoked. The attacker must be a meeting participant.
Recommendations
For versions prior to 2.4.3, update to version 2.4.3 or 2.5-alpha-1 to resolve the issue. As a temporary workaround, consider restricting access to the whiteboard feature for meeting participants until the update is applied.
Exploit
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigbluebutton