Skip to content

Grace period for whiteboard permissions

Low
antobinary published GHSA-v6p9-926c-6qfp Dec 15, 2022

Package

bbb-apps-akka (BigBlueButton)

Affected versions

<2.4.3

Patched versions

2.4.3, 2.5-alpha-1

Description

Impact

In the whiteboard we had a grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access was revoked. The attacker had to be a meeting participant.

Workarounds

No workaraounds

References

Patch in BigBlueButton 2.4.3 | #13853 | #13931
Patch in BigBlueButton 2.5-alpha-4 | #14575

For more information

If you have any questions or comments about this advisory:

Email us at security at bigbluebutton.org

Credits

We thank Nico Heitmann, Sven Hebrok, and Juraj Somorovsky from Paderborn University who examined the BigBlueButton code base and responsibly disclosed this vulnerability.

Severity

Low
2.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

CVE ID

CVE-2022-41963

Weaknesses

No CWEs