First published: Fri Dec 16 2022(Updated: )
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be a meeting presenter. This issue is patched in version 2.4.0. There are no workarounds.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bigbluebutton Bigbluebutton | =2.4-alpha1 | |
Bigbluebutton Bigbluebutton | =2.4-alpha2 | |
Bigbluebutton Bigbluebutton | =2.4-beta1 | |
Bigbluebutton Bigbluebutton | =2.4-beta2 | |
Bigbluebutton Bigbluebutton | =2.4-beta3 | |
Bigbluebutton Bigbluebutton | =2.4-beta4 | |
Bigbluebutton Bigbluebutton | =2.4-rc1 | |
Bigbluebutton Bigbluebutton | =2.4-rc2 | |
Bigbluebutton Bigbluebutton | =2.4-rc3 | |
Bigbluebutton Bigbluebutton | =2.4-rc4 | |
Bigbluebutton Bigbluebutton | =2.4-rc5 | |
Bigbluebutton Bigbluebutton | =2.4-rc6 | |
Bigbluebutton Bigbluebutton | =2.4-rc7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41964 is a vulnerability in BigBlueButton 2.4 release candidates that allows an attacker to see individual responses in an anonymous poll.
CVE-2022-41964 affects release candidates of BigBlueButton 2.4.
The severity of CVE-2022-41964 is medium with a CVSS score of 5.7.
To fix CVE-2022-41964, upgrade to BigBlueButton 2.4 release or later.
You can find more information about CVE-2022-41964 in the advisory on the GitHub security page of BigBlueButton.