BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The attacker must be a meeting participant. This issue is patched in version 2.4.3 an version 2.5-alpha-1
References
Link | Resource |
---|---|
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.3 | Release Notes Third Party Advisory |
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-v6p9-926c-6qfp | Patch Release Notes Third Party Advisory |
Configurations
Information
Published : 2022-12-16 06:15
Updated : 2022-12-20 09:46
NVD link : CVE-2022-41963
Mitre link : CVE-2022-41963
JSON object : View
CWE
CWE-281
Improper Preservation of Permissions
Products Affected
bigbluebutton
- bigbluebutton