CVE-2022-29236: Bigbluebutton
Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18 and 2.4-rc-6. There are currently no known workarounds.
Affected products
- Bigbluebutton Bigbluebutton: from 2.2.0, before 2.3.18 (fixed in 2.3.18); version 2.4 only
Published 2022-06-02. Last modified 2026-06-17.