Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them
Vulnerability Description
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy, allowing a session user to predict other users' conference session tokens and impersonate them. This issue is fixed in version 3.0.21.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
使用不充分的随机数
Vulnerability Title
BigBlueButton 加密问题漏洞
Vulnerability Description
BigBlueButton是BigBlueButton社区开源的一套开源的Web会议系统。 BigBlueButton 3.0.21之前版本存在加密问题漏洞,该漏洞源于bbb-web生成conference sessionToken值时随机性不足,可能导致会话用户预测其他用户的会议会话令牌并冒充他们。
CVSS Information
N/A
Vulnerability Type
N/A