ZeroHour

CVE-2022-41964

CVSS 3.1
5.7 medium
EPSS
<1%p44
Published
()
Modified
Description

BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be a meeting presenter. This issue is patched in version 2.4.0. There are no workarounds.

Vendors
bigbluebutton
Products
bigbluebutton
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.