Description
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.5Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: Low
Affected Packages3 packages
Also affects: Fedora 39, 40
🔴Vulnerability Details
4CVEListmoodle: BigBlueButton web service leaks meeting joining information to users who should not have access↗2024-06-18 ▶ OSVCVE-2024-38273: Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access↗2024-06-18 ▶ OSVMoodle BigBlueButton web service leaks meeting joining information↗2024-06-18 ▶ GHSAMoodle BigBlueButton web service leaks meeting joining information↗2024-06-18 ▶