← volver
CVE-2022-31039

Improper privilege management - Anyone can view room settings in GreenLight

CVSS 4.3 MEDIUMEPSS 0.6%CWE-269
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.3EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
27 jun 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Productos afectados
bigbluebutton · greenlight

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →