← back
CVE-2022-31039mediumCWE-269

Improper privilege management - Anyone can view room settings in GreenLight

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.7%
exploitation probability
0.7%top 52% of all CVEs
observed exploitation
nono source reports it
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N