Grace period for lock settings in public/private chats in BigBlueButton
Vulnerability Description
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a participant in the meeting. Versions 2.3.18 and 2.4.1 contain a patch for this issue. There are currently no known workarounds.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-29234
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-36vc-c338-6xjv
- https://github.com/bigbluebutton/bigbluebutton/pull/13850
- https://github.com/bigbluebutton/bigbluebutton/pull/14265
- https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18
- https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.1
More from bigbluebutton
View All →Affected Vendor
bigbluebutton
View all reports →