CVE-2022-29235

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-29235
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29235.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-29235
Aliases
  • GHSA-x82p-j22f-v4q6
Published
2022-06-01T23:25:18Z
Modified
2025-12-04T10:21:36.030654Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Limited data exposure for shared external videos in BigBlueButton
Details

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream to send the data only for users in the meeting. There are currently no known workarounds.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29235.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/bigbluebutton/bigbluebutton

Affected ranges

Type
GIT
Repo
https://github.com/bigbluebutton/bigbluebutton
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.2"
        },
        {
            "fixed": "2.3.18"
        }
    ]
}
Type
GIT
Repo
https://github.com/bigbluebutton/bigbluebutton
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.4-alpha-1"
        },
        {
            "fixed": "2.4-rc-6"
        }
    ]
}

Affected versions

2.*

2.4-rc-2

v2.*

v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.14
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4-alpha-1
v2.4-alpha-2
v2.4-beta-1
v2.4-beta-2
v2.4-beta-3
v2.4-beta-4
v2.4-rc-1
v2.4-rc-3
v2.4-rc-4
v2.4-rc-5

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29235.json"