« Volver al listado

CVE-2022-29236

Estado: ModificadaMedia (4.3)—

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18 and 2.4-rc-6. There are currently no known workarounds.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-29236",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "bigbluebutton",
          "product": "bigbluebutton",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.2, < 2.3.18"
            },
            {
              "status": "affected",
              "version": ">= 2.4-alpha-1, < 2.4-rc-6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-02T00:15:08.483",
  "references": [
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/pull/13803",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/pull/14265",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-p93g-r9gm-9v6r",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/pull/13803",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/pull/14265",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-p93g-r9gm-9v6r",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18 and 2.4-rc-6. There are currently no known workarounds."
    },
    {
      "lang": "es",
      "value": "BigBlueButton es un sistema de conferencias web de código abierto. A partir de la versión 2.2 y versiones hasta 2.3.18 y 2.4-rc-6, un atacante puede omitir las restricciones de acceso para dibujar en la pizarra. La comprobación de permisos es omitida inadvertidamente en el servidor, debido a un periodo de gracia introducido previamente. El atacante debe ser un participante de la reunión. El problema ha sido parcheado en versiones 2.3.18 y 2.4-rc-6. Actualmente no son conocidas mitigaciones"
    }
  ],
  "lastModified": "2026-06-17T04:39:53.443",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60814A0D-57C0-4407-B7DD-26A9D5C3DBB1",
              "versionEndExcluding": "2.3.18",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C136F53E-2EC5-433F-B354-88DA37689142"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "626A8774-BC38-4F11-A16B-918EC8740C82"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33735D00-C2AC-4FDA-B47B-B15D099F26F3"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98890F0C-2E60-4696-A6E5-F44FB2A1A5BD"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C916210-11BF-4F4C-AE3E-29D27135F3F9"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABB37B70-021E-48F6-B3D2-0790A4729A3C"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "407E0358-75E5-41D9-A624-3C15D2145DDE"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC135064-4919-4759-BC25-34C7868F6431"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0173198-BFAB-49E5-898E-173503C452C2"
            },
            {
              "criteria": "cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCB8C413-ECD9-47BF-963C-B3A0F25A1BD8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}