Security Advisory

CVE-2022-29234

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-06-01 23:20:14
Last updated 2025-04-23 18:20:10
Assigner GitHub_M
CVSS score 4.3
State PUBLISHED

Description

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a participant in the meeting. Versions 2.3.18 and 2.4.1 contain a patch for this issue. There are currently no known workarounds.