BigBlueButton是BigBlueButton社区的一套开源的Web会议系统。 BigBlueButton 2.2版本到2.3.9和2.4-beta-1 版本存在信息泄露漏洞,该漏洞源于服务会议公告聊天消息缺少信息保护措施和访问控制。攻击者可以利用该漏洞绕过访问控制从服务器上的不同会议中获取公共聊天消息的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bigbluebutton | bigbluebutton | >= 2.2, < 2.3.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-29169 | 7.5 HIGH | ReDoS on endpoint html5client/useragent in BigBlueButton |
| CVE-2022-29235 | 5.3 MEDIUM | Limited data exposure for shared external videos in BigBlueButton |
| CVE-2022-29233 | 4.3 MEDIUM | Improper access control for breakout rooms in BigBlue Button |
| CVE-2022-29234 | 4.3 MEDIUM | Grace period for lock settings in public/private chats in BigBlueButton |
| CVE-2022-29236 | 4.3 MEDIUM | Improper access control for pencil annotations in BigBlueButton |
No comments yet