SB2022060246 - Improper access control in BigBlueButton
Published: June 2, 2022 Updated: May 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2022-29232)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose the content of public chat messages from different meetings on the server.
The vulnerability exists due to improper access control in the public chat message access controls when handling chat message access across meetings. A remote user can participate in a meeting on the server to disclose the content of public chat messages from different meetings on the server.
Remediation
Install update from vendor's website.