First published: Mon Jun 27 2022(Updated: )
BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has been addressed in version 2.4.8 and 2.5.0. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bigbluebutton Bigbluebutton | >=2.4<2.4.8 | |
Bigbluebutton Bigbluebutton | =2.3.0 | |
Bigbluebutton Bigbluebutton | =2.4.9 | |
Bigbluebutton Bigbluebutton | =2.5-alpha1 | |
Bigbluebutton Bigbluebutton | =2.5-alpha2 | |
Bigbluebutton Bigbluebutton | =2.5-alpha3 | |
Bigbluebutton Bigbluebutton | =2.5-alpha4 | |
Bigbluebutton Bigbluebutton | =2.5-alpha5 | |
Bigbluebutton Bigbluebutton | =2.5-alpha6 | |
Bigbluebutton Bigbluebutton | =2.5-beta1 | |
Bigbluebutton Bigbluebutton | =2.5-beta2 | |
Bigbluebutton Bigbluebutton | =2.5-rc.1 | |
Bigbluebutton Bigbluebutton | =2.5-rc.2 | |
Bigbluebutton Bigbluebutton | =2.5-rc.3 | |
Bigbluebutton Bigbluebutton | =2.5-rc.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31064 is a vulnerability in the BigBlueButton web conferencing system that allows for cross-site scripting attacks in meetings with private chat enabled.
The severity of CVE-2022-31064 is medium, with a CVSS score of 5.4.
Versions 2.3.0 to 2.4.8 of BigBlueButton are affected by CVE-2022-31064.
CVE-2022-31064 occurs when the attacker (with xss in the name) starts a chat in the victim's client, executing JavaScript.
Yes, the BigBlueButton project has released a fix for CVE-2022-31064, which can be found in their GitHub repository.