Skip to content

Improper enforcement of moderator-only webcams setting

Moderate
antobinary published GHSA-j5g3-f74q-rvfq Dec 15, 2022

Package

No package listed

Affected versions

<2.5-alpha-1, <2.4-rc-6

Patched versions

2.5-alpha-1, 2.4-rc-6

Description

Impact

The moderators-only webcams lock setting was not enforced on the backend, which allowed the attacker to subscribe to viewers' webcams, even when the lock setting was applied. (The required streamId was being sent to all users even with lock setting applied).

Patches

v2.4-rc-6 (release)
v2.5-alpha-1 (release)

Workarounds

No Workarounds.

References

#13790

For more information

If you have any questions or comments about this advisory:

Email us at security at bigbluebutton.org

Credits

We thank Nico Heitmann, Sven Hebrok, and Juraj Somorovsky from Paderborn University who examined the BigBlueButton code base and responsibly disclosed this vulnerability.

Severity

Moderate
5.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CVE ID

CVE-2022-23488

Weaknesses

No CWEs