7.5

CVE-2022-23488

BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data

Improper enforcement of moderator-only webcams setting

BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the backend, which allows an attacker to subscribe to viewers' webcams, even when the lock setting is applied. (The required streamId was being sent to all users even with lock setting applied). This issue is fixed in version 2.4-rc-6.  There are no workarounds.
Mögliche Gegenmaßnahme
Server: No Workarounds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BigBlueButton ≫ BigBlueButton Version < 2.4
BigBlueButton ≫ BigBlueButton Version 2.4 Update alpha1
BigBlueButton ≫ BigBlueButton Version 2.4 Update alpha2
BigBlueButton ≫ BigBlueButton Version 2.4 Update beta1
BigBlueButton ≫ BigBlueButton Version 2.4 Update beta2
BigBlueButton ≫ BigBlueButton Version 2.4 Update beta3
BigBlueButton ≫ BigBlueButton Version 2.4 Update beta4
BigBlueButton ≫ BigBlueButton Version 2.4 Update rc1
BigBlueButton ≫ BigBlueButton Version 2.4 Update rc2
BigBlueButton ≫ BigBlueButton Version 2.4 Update rc3
BigBlueButton ≫ BigBlueButton Version 2.4 Update rc4
BigBlueButton ≫ BigBlueButton Version 2.4 Update rc5
Weitere Schwachstelleninformationen
SystemBigBlueButton
≫
Produkt Server
Version >= 0.0.0, < 2.4-rc-6
Version >= 2.5-alpha-1.0, < 2.5-alpha-1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.426
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-201 Insertion of Sensitive Information Into Sent Data

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6
Third Party Advisory
Release Notes
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-j5g3-f74q-rvfq
Patch
Third Party Advisory
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-j5g3-f74q-rvfq
Third Party Advisory