CVE-2022-36029: Bigbluebutton Greenlight

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.

Affected products

Published 2024-04-25. Last modified 2026-06-17.