MEDIUM
BigBlueButton contains Response leaks in anonymous polls
Published Dec 16, 2022
5.7
MEDIUMCVSS 3.1
EPSS 0.58%
Description
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be a meeting presenter. This issue is patched in version 2.4.0. There are no workarounds.
Affected products
-
- Version >= 2.4-alpha-1, < 2.4.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bigbluebutton | Bigbluebutton | n/a |
|
OR
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
- 2.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45070 Advisory
- https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-fgmj-rx7j-fqr4 x_refsource_CONFIRMPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-45070 | Advisory | |
| https://github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.0 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-fgmj-rx7j-fqr4 | x_refsource_CONFIRMPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 16, 2022
Updated Apr 17, 2025
Reserved Sep 30, 2022
Link CVE-2022-41964
CISA Vulnrichment
Updated Apr 17, 2025
ENISA EUVD
EUVD-2022-45070 Assigner GitHub_M
Published Dec 16, 2022
Updated Apr 17, 2025
Exploited since n/a
Link EUVD-2022-45070