CVE-2022-29234 Information
Jun 07, 2022
cve
Description
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and up to versions 2.3.18 and 2.4.1 an attacker could send messages to a locked chat within a grace period of 5s after the lock setting was enacted. The attacker needs to be a participant in the meeting. Versions 2.3.18 and 2.4.1 contain a patch for this issue. There are currently no known workarounds.
Reference
https://github.com/bigbluebutton/bigbluebutton/pull/13850 https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.1 https://github.com/bigbluebutton/bigbluebutton/pull/14265 https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18 https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-36vc-c338-6xjv
Share on: