CVE-2022-29233 is a medium-severity access control bypass vulnerability affecting BigBlueButton versions 2.2 through 2.3.17 and 2.4-rc-0. An authenticated attacker can exploit this flaw to gain unauthorized access to all breakout rooms within a meeting due to insufficient permission checks relying on internal IDs instead of user roles. The CVSS score of 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) indicates it can be exploited remotely with low complexity and privileges, leading to a low impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.3.18CPE matchmatch criteria | cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta1:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:beta2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.