CVE Vulnerabilities

CVE-2022-29235

Published: Jun 02, 2022 | Modified: Mar 08, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream to send the data only for users in the meeting. There are currently no known workarounds.

Affected Software

Name Vendor Start Version End Version
Bigbluebutton Bigbluebutton 2.2.0 (including) 2.3.18 (excluding)
Bigbluebutton Bigbluebutton 2.4-alpha1 (including) 2.4-alpha1 (including)
Bigbluebutton Bigbluebutton 2.4-alpha2 (including) 2.4-alpha2 (including)
Bigbluebutton Bigbluebutton 2.4-beta1 (including) 2.4-beta1 (including)
Bigbluebutton Bigbluebutton 2.4-beta2 (including) 2.4-beta2 (including)
Bigbluebutton Bigbluebutton 2.4-beta3 (including) 2.4-beta3 (including)
Bigbluebutton Bigbluebutton 2.4-beta4 (including) 2.4-beta4 (including)
Bigbluebutton Bigbluebutton 2.4-rc1 (including) 2.4-rc1 (including)
Bigbluebutton Bigbluebutton 2.4-rc3 (including) 2.4-rc3 (including)
Bigbluebutton Bigbluebutton 2.4-rc4 (including) 2.4-rc4 (including)
Bigbluebutton Bigbluebutton 2.4-rc5 (including) 2.4-rc5 (including)

References