CVE-2022-41964
16.12.2022, 18:15
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be a meeting presenter. This issue is patched in version 2.4.0. There are no workarounds.Enginsight
Vendor | Product | Version |
---|---|---|
bigbluebutton | bigbluebutton | 2.4:alpha1 |
bigbluebutton | bigbluebutton | 2.4:alpha2 |
bigbluebutton | bigbluebutton | 2.4:beta1 |
bigbluebutton | bigbluebutton | 2.4:beta2 |
bigbluebutton | bigbluebutton | 2.4:beta3 |
bigbluebutton | bigbluebutton | 2.4:beta4 |
bigbluebutton | bigbluebutton | 2.4:rc1 |
bigbluebutton | bigbluebutton | 2.4:rc2 |
bigbluebutton | bigbluebutton | 2.4:rc3 |
bigbluebutton | bigbluebutton | 2.4:rc4 |
bigbluebutton | bigbluebutton | 2.4:rc5 |
bigbluebutton | bigbluebutton | 2.4:rc6 |
bigbluebutton | bigbluebutton | 2.4:rc7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References