CVE-2022-41964: BigBlueButton contains Response leaks in anonymous polls
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be a meeting presenter. This issue is patched in version 2.4.0. There are no workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-41964?
CVE-2022-41964 is a vulnerability in BigBlueButton 2.4 release candidates that allows an attacker to see individual responses in an anonymous poll.
How does CVE-2022-41964 affect BigBlueButton?
CVE-2022-41964 affects release candidates of BigBlueButton 2.4.
What is the severity of CVE-2022-41964?
The severity of CVE-2022-41964 is medium with a CVSS score of 5.7.
How can I fix CVE-2022-41964?
To fix CVE-2022-41964, upgrade to BigBlueButton 2.4 release or later.
Where can I find more information about CVE-2022-41964?
You can find more information about CVE-2022-41964 in the advisory on the GitHub security page of BigBlueButton.