First published: Wed Jun 01 2022(Updated: )
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18 and 2.4-rc-6. There are currently no known workarounds.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bigbluebutton Bigbluebutton | >=2.2.0<2.3.18 | |
Bigbluebutton Bigbluebutton | =2.4-alpha1 | |
Bigbluebutton Bigbluebutton | =2.4-alpha2 | |
Bigbluebutton Bigbluebutton | =2.4-beta1 | |
Bigbluebutton Bigbluebutton | =2.4-beta2 | |
Bigbluebutton Bigbluebutton | =2.4-beta3 | |
Bigbluebutton Bigbluebutton | =2.4-beta4 | |
Bigbluebutton Bigbluebutton | =2.4-rc1 | |
Bigbluebutton Bigbluebutton | =2.4-rc3 | |
Bigbluebutton Bigbluebutton | =2.4-rc4 | |
Bigbluebutton Bigbluebutton | =2.4-rc5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29236 is a vulnerability in BigBlueButton, an open source web conferencing system, that allows an attacker to bypass access restrictions for drawing on the whiteboard.
BigBlueButton versions 2.2 up to 2.3.18 and 2.4-rc-6 are affected by CVE-2022-29236.
The severity of CVE-2022-29236 is medium with a CVSS score of 4.3.
An attacker can exploit CVE-2022-29236 by circumventing access restrictions for drawing on the whiteboard in affected versions of BigBlueButton.
Yes, a fix has been released for CVE-2022-29236. It is recommended to update to BigBlueButton version 2.3.18 or follow the provided patches in the GitHub references.