Vulnerabilities > CVE-2022-41963 - Improper Preservation of Permissions vulnerability in Bigbluebutton

047910
CVSS 3.1 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
high complexity
bigbluebutton
CWE-281

Summary

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The attacker must be a meeting participant. This issue is patched in version 2.4.3 an version 2.5-alpha-1

Vulnerable Configurations

Part Description Count
Application
Bigbluebutton
130

Common Weakness Enumeration (CWE)