<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Greenlight</title>
  <link>https://cvedaily.com/pages/tags/greenlight.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/greenlight.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Greenlight</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-36029 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36029</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36029</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36028 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36028</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36028</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31039 – Greenlight is a simple front-end interface for your BigBlueButton server. In aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31039</guid>
    <pubDate>Mon, 27 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31039</strong></p>
  <p>Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-26497 – BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26497</guid>
    <pubDate>Thu, 02 Jun 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-26497</strong></p>
  <p>BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27642 – A cross-site scripting (XSS) vulnerability exists in the 'merge account' functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27642</guid>
    <pubDate>Thu, 22 Oct 2020 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27642</strong></p>
  <p>A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27612 – Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27612</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27612</strong></p>
  <p>Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information leak to users in a room, or an information leak to outsiders if any user publishes a screenshot of a browser window.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26163 – BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26163</guid>
    <pubDate>Wed, 30 Sep 2020 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26163</strong></p>
  <p>BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26163">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
