Bigbluebutton
Source repositories
CVEs (58)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42803 | Med | 0.00 | 5.3 | 0.01 | Oct 30, 2023 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of… | ||
| CVE-2023-33176 | Med | 0.00 | 4.8 | 0.00 | Jun 26, 2023 | BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supply a URL from which the… | ||
| CVE-2020-27602 | Cri | 0.00 | 9.8 | 0.01 | Sep 29, 2022 | BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken. | ||
| CVE-2020-27601 | Low | 0.00 | 3.5 | 0.01 | Sep 29, 2022 | In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js. | ||
| CVE-2022-31065 | Med | 0.00 | 6.5 | 0.01 | Jun 27, 2022 | BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),… | ||
| CVE-2022-31064 | Med | 0.00 | 6.5 | 0.01 | Jun 27, 2022 | BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the… | ||
| CVE-2022-29236 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a… | ||
| CVE-2022-29235 | Med | 0.00 | 5.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the… | ||
| CVE-2022-29234 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a… | ||
| CVE-2022-29233 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of… | ||
| CVE-2022-29232 | Med | 0.00 | 6.5 | 0.01 | Jun 1, 2022 | BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a… | ||
| CVE-2022-29169 | Hig | 0.00 | 7.5 | 0.01 | Jun 1, 2022 | BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service… | ||
| CVE-2021-4143 | Med | 0.00 | 6.1 | 0.01 | Jan 19, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. | ||
| CVE-2020-28954 | Med | 0.00 | 5.3 | 0.01 | Nov 19, 2020 | web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name. | ||
| CVE-2020-28953 | Med | 0.00 | 4.3 | 0.01 | Nov 19, 2020 | In BigBlueButton before 2.2.29, a user can vote more than once in a single poll. | ||
| CVE-2020-27611 | Hig | 0.00 | 7.3 | 0.01 | Oct 21, 2020 | BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint. | ||
| CVE-2020-12443 | Cri | 0.00 | 9.8 | 0.04 | Apr 29, 2020 | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to… | ||
| CVE-2020-12113 | Med | 0.00 | 6.1 | 0.01 | Apr 23, 2020 | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used. |
- risk 0.00cvss 5.3epss 0.01
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of…
- risk 0.00cvss 4.8epss 0.00
BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supply a URL from which the…
- risk 0.00cvss 9.8epss 0.01
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
- risk 0.00cvss 3.5epss 0.01
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.
- risk 0.00cvss 6.5epss 0.01
BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript),…
- risk 0.00cvss 6.5epss 0.01
BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a…
- risk 0.00cvss 5.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of…
- risk 0.00cvss 6.5epss 0.01
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a…
- risk 0.00cvss 7.5epss 0.01
BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service…
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
- risk 0.00cvss 5.3epss 0.01
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
- risk 0.00cvss 4.3epss 0.01
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
- risk 0.00cvss 7.3epss 0.01
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
- risk 0.00cvss 9.8epss 0.04
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to…
- risk 0.00cvss 6.1epss 0.01
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
Page 3 of 3