CVE-2022-29235

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream to send the data only for users in the meeting. There are currently no known workarounds.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta3:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta4:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc3:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc4:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc5:*:*:*:*:*:*

History

08 Mar 2024, 19:15

Type Values Removed Values Added
Summary (en) BigBlueButton is an open source web conferencing system. Starting in version 2.2 and up to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream to send the data only for users in the meeting. There are currently no known workarounds. (en) BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream to send the data only for users in the meeting. There are currently no known workarounds.

21 Jul 2023, 16:54

Type Values Removed Values Added
CWE CWE-200 NVD-CWE-Other

09 Jun 2022, 15:32

Type Values Removed Values Added
References (MISC) https://github.com/bigbluebutton/bigbluebutton/pull/13788 - (MISC) https://github.com/bigbluebutton/bigbluebutton/pull/13788 - Patch, Third Party Advisory
References (CONFIRM) https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-x82p-j22f-v4q6 - (CONFIRM) https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-x82p-j22f-v4q6 - Patch, Third Party Advisory
References (MISC) https://github.com/bigbluebutton/bigbluebutton/pull/14265 - (MISC) https://github.com/bigbluebutton/bigbluebutton/pull/14265 - Patch, Third Party Advisory
References (MISC) https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18 - (MISC) https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18 - Release Notes, Third Party Advisory
References (MISC) https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6 - (MISC) https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6 - Release Notes, Third Party Advisory
First Time Bigbluebutton bigbluebutton
Bigbluebutton
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.3
CPE cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta3:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc5:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc3:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc4:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc1:*:*:*:*:*:*
cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta4:*:*:*:*:*:*

02 Jun 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-02 00:15

Updated : 2024-03-08 19:15


NVD link : CVE-2022-29235

Mitre link : CVE-2022-29235

CVE.ORG link : CVE-2022-29235


JSON object : View

Products Affected

bigbluebutton

  • bigbluebutton
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor