CVE-2024-38273: Fedoraproject Fedora
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
Affected products
- Fedoraproject Fedora: version 39 only; version 40 only
- Moodle Moodle: from 4.1.0, before 4.1.11 (fixed in 4.1.11); from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.5 (fixed in 4.3.5); version 4.4.0 only
Published 2024-06-18. Last modified 2026-06-17.