BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The attacker must be a meeting participant. This issue is patched in version 2.4.3 an version 2.5-alpha-1
References
Link | Resource |
---|---|
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.3 | Release Notes Third Party Advisory |
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-v6p9-926c-6qfp | Patch Release Notes Third Party Advisory |
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.3 | Release Notes Third Party Advisory |
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-v6p9-926c-6qfp | Patch Release Notes Third Party Advisory |
Configurations
History
21 Nov 2024, 07:24
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.3 - Release Notes, Third Party Advisory | |
References | () https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-v6p9-926c-6qfp - Patch, Release Notes, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.7 |
Information
Published : 2022-12-16 14:15
Updated : 2024-11-21 07:24
NVD link : CVE-2022-41963
Mitre link : CVE-2022-41963
CVE.ORG link : CVE-2022-41963
JSON object : View
Products Affected
bigbluebutton
- bigbluebutton
CWE
CWE-281
Improper Preservation of Permissions