Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any rooms settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a rooms settings. This issue has been patched in release version 2.12.6.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Greenlight | Bigbluebutton | * | 2.12.6 (excluding) |