Medium severity4.3NVD Advisory· Published Dec 16, 2022· Updated Jun 17, 2026
CVE-2022-23490
CVE-2022-23490
Description
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update the client UI, but does give the attacker access to the contents of the collection, which include the individual poll responses. This issue is patched in version 2.4.0. There are no workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*range: <2.4.0
- (no CPE)range: <2.4.0
- (no CPE)range: < 2.4.0
Patches
Vulnerability mechanics
References
2- github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-4qgc-xhw5-6qfgnvdPatchThird Party Advisory
- github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4.0nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.