<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Greenlight (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/greenlight.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/greenlight-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Greenlight (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-36029 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36029</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36029</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36028 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36028</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36028</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26163 – BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26163</guid>
    <pubDate>Wed, 30 Sep 2020 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26163</strong></p>
  <p>BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26163">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
