Greenlight BigBlueButton Servers Vulnerable to Open Redirect
CVE-2022-36028
6.1MEDIUM
What is CVE-2022-36028?
Greenlight, an end-user interface for BigBlueButton servers, is susceptible to an open redirect vulnerability due to improper validation of the 'return_to' cookie value. This oversight allows malicious actors to redirect users to untrusted destinations after login. It is crucial for users operating versions prior to 2.13.0 to upgrade to the patched version to mitigate any potential security risks associated with this vulnerability.
Affected Version(s)
greenlight 0 < 2.13.0
