Improper access control in BigBlueButton - CVE-2022-29235
Published: June 1, 2022 / Updated: May 14, 2026
BigBlueButton
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose limited information about a shared external video.
The vulnerability exists due to improper access control in the external video data stream when obtaining a meeting identifier for a meeting on the server. A remote attacker can access information such as the current timestamp and play or pause state to disclose limited information about a shared external video.