Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.
References
Link | Resource |
---|---|
https://github.com/bigbluebutton/greenlight/commit/20fe1ee71b5703fcc4ed698a959ad224fed19623 | Patch |
https://huntr.com/bounties/ba5834bd-1f04-4936-8e93-2442d45403bahttps:// | Third Party Advisory Broken Link |
https://github.com/bigbluebutton/greenlight/commit/20fe1ee71b5703fcc4ed698a959ad224fed19623 | Patch |
https://huntr.com/bounties/ba5834bd-1f04-4936-8e93-2442d45403bahttps:// | Third Party Advisory Broken Link |
Configurations
History
24 Apr 2025, 13:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/bigbluebutton/greenlight/commit/20fe1ee71b5703fcc4ed698a959ad224fed19623 - Patch | |
References | () https://huntr.com/bounties/ba5834bd-1f04-4936-8e93-2442d45403bahttps:// - Third Party Advisory, Broken Link | |
First Time |
Bigbluebutton
Bigbluebutton greenlight |
|
CPE | cpe:2.3:a:bigbluebutton:greenlight:*:*:*:*:*:*:*:* |
Information
Published : 2024-04-25 21:15
Updated : 2025-04-24 13:45
NVD link : CVE-2022-36028
Mitre link : CVE-2022-36028
CVE.ORG link : CVE-2022-36028
JSON object : View
Products Affected
bigbluebutton
- greenlight
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')