Greenlight BigBlueButton Servers Vulnerable to Open Redirect
CVE-2022-36029
6.1MEDIUM
What is CVE-2022-36029?
The Greenlight end-user interface for BigBlueButton servers has a vulnerability allowing for open redirects due to an unchecked value in the return_to cookie. This weakness can be exploited to redirect users to malicious websites, possibly facilitating phishing attacks or other security breaches. The issue is addressed in version 2.13.0 of Greenlight, which contains a patch that rectifies this vulnerability.
Affected Version(s)
greenlight 0 < 2.13.0
