{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T14:43:17.463","vulnerabilities":[{"cve":{"id":"CVE-2022-29236","sourceIdentifier":"security-advisories@github.com","published":"2022-06-02T00:15:08.483","lastModified":"2026-06-17T04:39:53.443","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18 and 2.4-rc-6. There are currently no known workarounds."},{"lang":"es","value":"BigBlueButton es un sistema de conferencias web de código abierto. A partir de la versión 2.2 y versiones hasta 2.3.18 y 2.4-rc-6, un atacante puede omitir las restricciones de acceso para dibujar en la pizarra. La comprobación de permisos es omitida inadvertidamente en el servidor, debido a un periodo de gracia introducido previamente. El atacante debe ser un participante de la reunión. El problema ha sido parcheado en versiones 2.3.18 y 2.4-rc-6. Actualmente no son conocidas mitigaciones"}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"bigbluebutton","product":"bigbluebutton","versions":[{"version":">= 2.2, < 2.3.18","status":"affected"},{"version":">= 2.4-alpha-1, < 2.4-rc-6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-285"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*","versionStartIncluding":"2.2.0","versionEndExcluding":"2.3.18","matchCriteriaId":"60814A0D-57C0-4407-B7DD-26A9D5C3DBB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*","matchCriteriaId":"C136F53E-2EC5-433F-B354-88DA37689142"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*","matchCriteriaId":"626A8774-BC38-4F11-A16B-918EC8740C82"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:*","matchCriteriaId":"33735D00-C2AC-4FDA-B47B-B15D099F26F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:*","matchCriteriaId":"98890F0C-2E60-4696-A6E5-F44FB2A1A5BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta3:*:*:*:*:*:*","matchCriteriaId":"0C916210-11BF-4F4C-AE3E-29D27135F3F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta4:*:*:*:*:*:*","matchCriteriaId":"ABB37B70-021E-48F6-B3D2-0790A4729A3C"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc1:*:*:*:*:*:*","matchCriteriaId":"407E0358-75E5-41D9-A624-3C15D2145DDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc3:*:*:*:*:*:*","matchCriteriaId":"EC135064-4919-4759-BC25-34C7868F6431"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc4:*:*:*:*:*:*","matchCriteriaId":"A0173198-BFAB-49E5-898E-173503C452C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:rc5:*:*:*:*:*:*","matchCriteriaId":"CCB8C413-ECD9-47BF-963C-B3A0F25A1BD8"}]}]}],"references":[{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/13803","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/14265","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18","source":"security-advisories@github.com","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6","source":"security-advisories@github.com","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-p93g-r9gm-9v6r","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/13803","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/14265","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.18","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-rc-6","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"]},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-p93g-r9gm-9v6r","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]}]}}]}