CVE-2022-41960 - CVE House
Back to Database
Status published Medium CVE-2022-41960

BigBlueButton contains DoS via failed authToken validation

Vulnerability Description

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` using a victim's userId, meetingId, and an invalid authToken. This forces the victim to leave the conference, because the resulting verification failure is also observed and handled by the victim's client. The attacker must be a participant in any meeting on the server. This issue is patched in version 2.4.3. There are no workarounds.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-41960

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

bigbluebutton

View all reports →

Affected Software

bigbluebutton
Vulnerable Versions:
< 2.4.3

Timeline

Official Publish: December 15th, 2022
Last Modified: April 17th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)