4.3

CVE-2022-41960

BigBlueButton contains DoS via failed authToken validation

DoS via failed authToken validation

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` using a victim's userId, meetingId, and an invalid authToken. This forces the victim to leave the conference, because the resulting verification failure is also observed and handled by the victim's client. The attacker must be a participant in any meeting on the server. This issue is patched in version 2.4.3. There are no workarounds.
Mögliche Gegenmaßnahme
Server: No Workarounds
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BigBlueButtonBigBlueButton Version < 2.4.3
Weitere Schwachstelleninformationen
SystemBigBlueButton
Produkt Server
Version >= 0.0.0, < 2.4.3
Version >= 2.5-alpha-1.0, < 2.5-alpha-1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.278
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
security-advisories@github.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.3
Third Party Advisory
Release Notes
https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.5-alpha-1
Third Party Advisory
Release Notes
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-rgjp-3r74-g4cm
Third Party Advisory
Release Notes
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-rgjp-3r74-g4cm
Third Party Advisory