BigBlueButton 2.2.34 was released!

126 views
Skip to first unread message

Anton Georgiev

unread,
Mar 3, 2021, 2:55:59 PM3/3/21
to BigBlueButton-dev
Hi Everyone,

We are pleased to announce BigBlueButton 2.2.34.

This release of BigBlueButton 2.2 brings in some security fixes and packages improvements.

The full release notes are here

To install/upgrade, see

To try out the latest release, visit  https://test.bigbluebutton.org/

If you want to report any potential security issues with BigBlueButton, please e-mail us at secu...@bigbluebutton.org

Regards,
Anton

Sakis

unread,
Mar 3, 2021, 3:30:11 PM3/3/21
to BigBlueButton-dev

Hello,
I have set up a server with bbb 2.2.33 and greenlight and I have customized greenlight according this.
Now if I run the script to update bbb what will happen with customizations?
Would be better to update just by sudo apt-get update?

Tobias Fiebig

unread,
Mar 3, 2021, 5:31:30 PM3/3/21
to bigblueb...@googlegroups.com

Heho,

I just rolled this out, and it seems like downloading pads is broken (using the pad in the room still works).

 

Looking at #11535 I am not entirely sure if there was maybe a change forgotten? The change to bbb-web.nginx is in, but pad downloads still give me a 401.

 

Met vriendelijke groet,

 

Dr.-Ing. Tobias Fiebig

Assistant Professor / Universitair Docent

TU Delft - Faculty of Technology, Policy and Management (TBM)

 

T +31 (0)15 27 85700

t.fi...@tudelft.nl

 

My working day may not be your working day. Please do not feel obliged to reply to this email outside of your normal working hours.

--
You received this message because you are subscribed to the Google Groups "BigBlueButton-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to bigbluebutton-...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bigbluebutton-dev/48a5153a-2fa3-4cda-bb9b-bfbe499ccdd6n%40googlegroups.com.

Tobias Fiebig

unread,
Mar 3, 2021, 5:48:38 PM3/3/21
to bigblueb...@googlegroups.com

Followup:

Removing auth indeed makes downloads work again; Still think that this is not really how it should look like. 😉

 

16     #auth_request /bigbluebutton/connection/validatePad;                       

17     #auth_request_set $auth_status $upstream_status; 

 

Met vriendelijke groet,

 

Dr.-Ing. Tobias Fiebig

Assistant Professor / Universitair Docent

TU Delft - Faculty of Technology, Policy and Management (TBM)

 

T +31 (0)15 27 85700

t.fi...@tudelft.nl

 

My working day may not be your working day. Please do not feel obliged to reply to this email outside of your normal working hours.

 

Tobias Fiebig

unread,
Mar 3, 2021, 5:58:17 PM3/3/21
to bigblueb...@googlegroups.com

And the same holds for reverting to:

 

16     auth_request /bigbluebutton/connection/checkAuthorization;                 

17     auth_request_set $auth_status $upstream_status;

 

Which, according to the change in #11535 to UrlMappings.groovy should not work anymore? Furthermore, it seems like the commit is not adding an endpoint for validatePad?

 

Lemme file a ticket…

Tobias Fiebig

unread,
Mar 3, 2021, 6:10:45 PM3/3/21
to bigblueb...@googlegroups.com

Ok, filed #11545, sorry for rubberducking the ML.

Paulo Lanzarin

unread,
Mar 3, 2021, 6:31:10 PM3/3/21
to bigblueb...@googlegroups.com
> Which, according to the change in #11535 to UrlMappings.groovy should not work anymore? Furthermore, it seems like the commit is not adding an endpoint for validatePad?

Hey,

checkAuthorization and validatePad are internal routes, so they don't need to be in UrlMappings. So they still work as expected.

Tobias Fiebig

unread,
Mar 3, 2021, 6:34:53 PM3/3/21
to bigblueb...@googlegroups.com

Ok, good to know, thanks; I am not too deep in the codebase.

 

Should also reduce the potential sec. impact of my hotfix (and explains why it worked 😉).

 

Met vriendelijke groet,

 

Dr.-Ing. Tobias Fiebig

Assistant Professor / Universitair Docent

TU Delft - Faculty of Technology, Policy and Management (TBM)

 

T +31 (0)15 27 85700

t.fi...@tudelft.nl

 

My working day may not be your working day. Please do not feel obliged to reply to this email outside of your normal working hours.

 

Fred Dixon

unread,
Mar 3, 2021, 6:51:48 PM3/3/21
to BigBlueButton-dev
Hi Tobias,

Thanks for finding the issue so quickly.  We can reproduce it on our end and we've got a fix merged in that we are testing now



Regards,... Fred



--
BigBlueButton Developer

Like BigBlueButton?  Tweet us at @bigbluebutton

Tobias Fiebig

unread,
Mar 3, 2021, 6:57:23 PM3/3/21
to bigblueb...@googlegroups.com

Awesome, thanks. Is it worth it to stay awake for 2.2.35? 😉

 

Met vriendelijke groet,

 

Dr.-Ing. Tobias Fiebig

Assistant Professor / Universitair Docent

TU Delft - Faculty of Technology, Policy and Management (TBM)

 

T +31 (0)15 27 85700

t.fi...@tudelft.nl

 

My working day may not be your working day. Please do not feel obliged to reply to this email outside of your normal working hours.

 

Fred Dixon

unread,
Mar 3, 2021, 7:55:46 PM3/3/21
to BigBlueButton-dev
We should have it for you when you wake up tomorrow AM!

Regards,... Fred

Reply all
Reply to author
Forward
0 new messages