Lucene search

K
cveGitHub_MCVE-2022-29236
HistoryJun 02, 2022 - 12:15 a.m.

CVE-2022-29236

2022-06-0200:15:08
CWE-285
GitHub_M
web.nvd.nist.gov
71
10
bigbluebutton
web conferencing
access restriction
cve-2022-29236
security vulnerability
patch

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

33.3%

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18 and 2.4-rc-6. There are currently no known workarounds.

Affected configurations

Nvd
Vulners
Node
bigbluebuttonbigbluebuttonRange2.2.02.3.18
OR
bigbluebuttonbigbluebuttonMatch2.4alpha1
OR
bigbluebuttonbigbluebuttonMatch2.4alpha2
OR
bigbluebuttonbigbluebuttonMatch2.4beta1
OR
bigbluebuttonbigbluebuttonMatch2.4beta2
OR
bigbluebuttonbigbluebuttonMatch2.4beta3
OR
bigbluebuttonbigbluebuttonMatch2.4beta4
OR
bigbluebuttonbigbluebuttonMatch2.4rc1
OR
bigbluebuttonbigbluebuttonMatch2.4rc3
OR
bigbluebuttonbigbluebuttonMatch2.4rc4
OR
bigbluebuttonbigbluebuttonMatch2.4rc5
VendorProductVersionCPE
bigbluebuttonbigbluebutton*cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta3:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta4:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc1:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc3:*:*:*:*:*:*
bigbluebuttonbigbluebutton2.4cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc4:*:*:*:*:*:*
Rows per page:
1-10 of 111

CNA Affected

[
  {
    "vendor": "bigbluebutton",
    "product": "bigbluebutton",
    "versions": [
      {
        "version": ">= 2.2, < 2.3.18",
        "status": "affected"
      },
      {
        "version": ">= 2.4-alpha-1, < 2.4-rc-6",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.5

Confidence

High

EPSS

0.001

Percentile

33.3%

Related for CVE-2022-29236