Vendor CVEs
Bigbluebutton
All CVEs
65 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31039 | Med | 0.00 | 4.3 | 0.01 | Jun 27, 2022 | Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has… | ||
| CVE-2022-29236 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a… | ||
| CVE-2022-29235 | Med | 0.00 | 5.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the… | ||
| CVE-2022-29234 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a… | ||
| CVE-2022-29233 | Med | 0.00 | 4.3 | 0.01 | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of… | ||
| CVE-2022-29232 | Med | 0.00 | 6.5 | 0.01 | Jun 1, 2022 | BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a… | ||
| CVE-2022-29169 | Hig | 0.00 | 7.5 | 0.01 | Jun 1, 2022 | BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service… | ||
| CVE-2021-4143 | Med | 0.00 | 6.1 | 0.01 | Jan 19, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. | ||
| CVE-2020-28954 | Med | 0.00 | 5.3 | 0.01 | Nov 19, 2020 | web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name. | ||
| CVE-2020-28953 | Med | 0.00 | 4.3 | 0.01 | Nov 19, 2020 | In BigBlueButton before 2.2.29, a user can vote more than once in a single poll. | ||
| CVE-2020-27642 | Med | 0.00 | 6.1 | 0.01 | Oct 22, 2020 | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6. | ||
| CVE-2020-27611 | Hig | 0.00 | 7.3 | 0.01 | Oct 21, 2020 | BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint. | ||
| CVE-2020-26163 | Hig | 0.00 | 8.8 | 0.02 | Sep 30, 2020 | BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link. | ||
| CVE-2020-12443 | Cri | 0.00 | 9.8 | 0.04 | Apr 29, 2020 | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to… | ||
| CVE-2020-12113 | Med | 0.00 | 6.1 | 0.01 | Apr 23, 2020 | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used. |
- risk 0.00cvss 4.3epss 0.01
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a…
- risk 0.00cvss 5.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a…
- risk 0.00cvss 4.3epss 0.01
BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of…
- risk 0.00cvss 6.5epss 0.01
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a…
- risk 0.00cvss 7.5epss 0.01
BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service…
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
- risk 0.00cvss 5.3epss 0.01
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
- risk 0.00cvss 4.3epss 0.01
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
- risk 0.00cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
- risk 0.00cvss 7.3epss 0.01
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
- risk 0.00cvss 8.8epss 0.02
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
- risk 0.00cvss 9.8epss 0.04
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to…
- risk 0.00cvss 6.1epss 0.01
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
Page 2 of 2