{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-01T12:44:00.200","vulnerabilities":[{"cve":{"id":"CVE-2024-38518","sourceIdentifier":"security-advisories@github.com","published":"2024-06-28T21:15:03.180","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those parameters may be \"role=moderator\", allowing an attacker to join a meeting as moderator using a join link that was originally created for viewer access. This vulnerability has been patched in version(s) 2.6.18, 2.7.8 and 3.0.0-alpha.7."},{"lang":"es","value":"BigBlueButton es un aula virtual de código abierto diseñada para ayudar a los profesores a enseñar y a los alumnos a aprender. Un atacante con un enlace de entrada válido para una reunión puede engañar a BigBlueButton para que genere un enlace de entrada firmado con parámetros adicionales. Uno de esos parámetros puede ser \"rol=moderador\", lo que permite a un atacante unirse a una reunión como moderador utilizando un enlace para unirse que se creó originalmente para el acceso de los espectadores. Esta vulnerabilidad ha sido parcheada en las versiones 2.6.18, 2.7.8 y 3.0.0-alpha.7."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.1,"impactScore":2.5}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/a9d436accdcd26ea66bed9f391488ac128cd62d1","source":"security-advisories@github.com"},{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/ea6e9461dceae8fa593543d8c686f77bb8677e72","source":"security-advisories@github.com"},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/20279","source":"security-advisories@github.com"},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-4m48-49h7-f3c4","source":"security-advisories@github.com"},{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/a9d436accdcd26ea66bed9f391488ac128cd62d1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/bigbluebutton/bigbluebutton/commit/ea6e9461dceae8fa593543d8c686f77bb8677e72","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/bigbluebutton/bigbluebutton/pull/20279","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-4m48-49h7-f3c4","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}