BigBlueButton是BigBlueButton社区的一套开源的Web会议系统。 BigBlueButton 2.2 到 2.3.19、2.4.7 和 2.5.0-beta.2 之前版本存在输入验证错误漏洞,该漏洞源于容易受到正则表达式拒绝服务 (ReDoS) 攻击。攻击者利用该漏洞可以通过使用特定的正则表达式对 bbb-html5 服务造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bigbluebutton | bigbluebutton | >= 2.2, < 2.3.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-29232 | 6.5 MEDIUM | Exposure of messages in BigBlueButton public chats |
| CVE-2022-29235 | 5.3 MEDIUM | Limited data exposure for shared external videos in BigBlueButton |
| CVE-2022-29233 | 4.3 MEDIUM | Improper access control for breakout rooms in BigBlue Button |
| CVE-2022-29234 | 4.3 MEDIUM | Grace period for lock settings in public/private chats in BigBlueButton |
| CVE-2022-29236 | 4.3 MEDIUM | Improper access control for pencil annotations in BigBlueButton |
No comments yet