BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update the client UI, but does give the attacker access to the contents of the collection, which include the individual poll responses. This issue is patched in version 2.4.0. There are no workarounds.
History

Thu, 17 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-17T14:34:58.102Z

Reserved: 2022-01-19T21:23:53.762Z

Link: CVE-2022-23490

cve-icon Vulnrichment

Updated: 2024-08-03T03:43:46.126Z

cve-icon NVD

Status : Modified

Published: 2022-12-16T22:15:08.743

Modified: 2024-11-21T06:48:40.130

Link: CVE-2022-23490

cve-icon Redhat

No data.