VulnerabilityModified
CVE-2022-31039
In affected versions an attacker can view any room's settings even though they are not authorized to do so.
MEDIUM 5.3EPSS 0.67%
Does this matter?
Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.
Description
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269, CWE-863
- Affected
- bigbluebutton/greenlight
- Source
- security-advisories@github.com
References
- https://github.com/bigbluebutton/greenlight/pull/3508Patch, Third Party Advisory
- https://github.com/bigbluebutton/greenlight/security/advisories/GHSA-phh8-3v6v-7498Patch, Third Party Advisory
- https://github.com/bigbluebutton/greenlight/pull/3508Patch, Third Party Advisory
- https://github.com/bigbluebutton/greenlight/security/advisories/GHSA-phh8-3v6v-7498Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.