CVE-2021-4143: Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton
Published Jan 19, 2022
·Updated
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
Affected Software
1 affected component
BigBlueButton BigBlueButton<2.4.0
Remediation
Event History
Jan 19, 2022
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-4143?
The severity of CVE-2021-4143 is high.
2
How does CVE-2021-4143 affect the Bigbluebutton software?
CVE-2021-4143 affects the Bigbluebutton software prior to version 2.4.0.
3
What is the Common Weakness Enumeration (CWE) associated with CVE-2021-4143?
The Common Weakness Enumeration (CWE) associated with CVE-2021-4143 is CWE-79.
4
How can I fix CVE-2021-4143?
To fix CVE-2021-4143, you need to update Bigbluebutton to version 2.4.0 or higher.
5
Where can I find more information about CVE-2021-4143?
You can find more information about CVE-2021-4143 at the following references: [GitHub Commit](https://github.com/bigbluebutton/bigbluebutton/commit/62040bdcb3c2f993ba72ab89f4db2015e18d1706) and [Huntr Bounty](https://huntr.dev/bounties/e67603e6-8497-4ab6-b93a-02c26407d443).