{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T23:52:16.088","vulnerabilities":[{"cve":{"id":"CVE-2022-29235","sourceIdentifier":"security-advisories@github.com","published":"2022-06-02T00:15:08.390","lastModified":"2026-06-17T04:39:53.330","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream to send the data only for users in the meeting. There are currently no known workarounds."},{"lang":"es","value":"BigBlueButton es un sistema de conferencias web de código abierto. A partir de la versión 2.2 y versiones hasta 2.3.18 y 2.4-rc-6, un atacante que sea capaz de obtener el identificador de una reunión en un servidor puede encontrar información relacionada con un vídeo externo que esta siendo compartiendo, como la marca de tiempo actual y la reproducción/pausa. El problema ha sido parcheado en versiones 2.3.18 y 2.4-rc-6, al modificar el flujo para enviar los datos sólo para usuarios de la reunión. Actualmente no son conocidas mitigaciones"}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"bigbluebutton","product":"bigbluebutton","versions":[{"version":">= 2.2, < 2.3.18","status":"affected"},{"version":">= 2.4-alpha-1, < 2.4-rc-6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*","versionStartIncluding":"2.2.0","versionEndExcluding":"2.3.18","matchCriteriaId":"60814A0D-57C0-4407-B7DD-26A9D5C3DBB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*","matchCriteriaId":"C136F53E-2EC5-433F-B354-88DA37689142"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*","matchCriteriaId":"626A8774-BC38-4F11-A16B-918EC8740C82"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:*","matchCriteriaId":"33735D00-C2AC-4FDA-B47B-B15D099F26F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:*","matchCriteriaId":"98890F0C-2E60-4696-A6E5-F44FB2A1A5BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta3:*:*:*:*:*:*","matchCriteriaId":"0C916210-11BF-4F4C-AE3E-29D27135F3F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta4:*:*:*:*:*:*","matchCriteriaId":"ABB37B70-021E-48F6-B3D2-0790A4729A3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc1:*:*:*:*:*:*","matchCriteriaId":"407E0358-75E5-41D9-A624-3C15D2145DDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc3:*:*:*:*:*:*","matchCriteriaId":"EC135064-4919-4759-BC25-34C7868F6431"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc4:*:*:*:*:*:*","matchCriteriaId":"A0173198-BFAB-49E5-898E-173503C452C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc5:*:*:*:*:*:*","matchCriteriaId":"CCB8C413-ECD9-47BF-963C-B3A0F25A1BD8"}]}]}],"references":[{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/13788","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/14265","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18","source":"security-advisories@github.com","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6","source":"security-advisories@github.com","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-x82p-j22f-v4q6","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/13788","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/14265","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-x82p-j22f-v4q6","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]}]}}]}