Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-29233

Опубликовано: 02 июн. 2022
Источник: nvd
CVSS3: 4.3
CVSS2: 5
EPSS Низкий

Описание

BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of internal ids rather than on verification of the role of the user. Versions 2.3.18 and 2.4-rc-1 contain a patch for this issue. There are currently no known workarounds.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*
Версия от 2.2.0 (включая) до 2.3.18 (исключая)
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta3:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta4:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00338
Низкий

4.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-285

EPSS

Процентиль: 56%
0.00338
Низкий

4.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-285