CVE Vulnerabilities

CVE-2022-31039

Improper Privilege Management

Published: Jun 27, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any rooms settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a rooms settings. This issue has been patched in release version 2.12.6.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Greenlight Bigbluebutton * 2.12.6 (excluding)

Potential Mitigations

References