Fedora Account System
Red Hat Associate
Red Hat Customer
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. Issue summary: BigBlueButton web service leaks meeting joining information to users who should not have access Severity/Risk: Minor Versions affected: 4.4, 4.3 to 4.3.4, 4.2 to 4.2.7, 4.1 to 4.1.10 and earlier unsupported versions Versions fixed: 4.4.1, 4.3.5, 4.2.8 and 4.1.11 Issue no.: MDL-81778 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-81778
Created moodle tracking bugs for this issue: Affects: epel-all [bug 2292944] Affects: fedora-all [bug 2292945]