CVE Vulnerabilities

CVE-2022-31039

Improper Privilege Management

Published: Jun 27, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any rooms settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a rooms settings. This issue has been patched in release version 2.12.6.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
GreenlightBigbluebutton*2.12.6 (excluding)

Potential Mitigations

References