SB2022060246 - Improper access control in BigBlueButton



SB2022060246 - Improper access control in BigBlueButton

Published: June 2, 2022 Updated: May 18, 2026

Security Bulletin ID SB2022060246
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2022-29232)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose the content of public chat messages from different meetings on the server.

The vulnerability exists due to improper access control in the public chat message access controls when handling chat message access across meetings. A remote user can participate in a meeting on the server to disclose the content of public chat messages from different meetings on the server.


Remediation

Install update from vendor's website.