GHSA-x29x-qwvx-fxr2
GitHub Security Advisory
Moodle BigBlueButton web service leaks meeting joining information
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
Affected Packages
Packagist
moodle/moodle
Affected versions:
4.4.0-beta
(fixed in 4.4.1)
Packagist
moodle/moodle
Affected versions:
4.3.0-beta
(fixed in 4.3.5)
Packagist
moodle/moodle
Affected versions:
4.2.0-beta
(fixed in 4.2.8)
Packagist
moodle/moodle
Affected versions:
0
(fixed in 4.1.11)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 16, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.