漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Exposure of messages in BigBlueButton public chats
Vulnerability Description
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a participant in a meeting on the server. BigBlueButton versions 2.3.9 and 2.4-beta-1 contain a patch for this issue. There are currently no known workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
BigBlueButton 信息泄露漏洞
Vulnerability Description
BigBlueButton是BigBlueButton社区的一套开源的Web会议系统。 BigBlueButton 2.2版本到2.3.9和2.4-beta-1 版本存在信息泄露漏洞,该漏洞源于服务会议公告聊天消息缺少信息保护措施和访问控制。攻击者可以利用该漏洞绕过访问控制从服务器上的不同会议中获取公共聊天消息的内容。
CVSS Information
N/A
Vulnerability Type
N/A