VYPR
Medium severity4.3NVD Advisory· Published Dec 16, 2022· Updated Jun 17, 2026

CVE-2022-23490

CVE-2022-23490

Description

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update the client UI, but does give the attacker access to the contents of the collection, which include the individual poll responses. This issue is patched in version 2.4.0. There are no workarounds.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*range: <2.4.0
    • (no CPE)range: <2.4.0
    • (no CPE)range: < 2.4.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.

CVE-2022-23490 · Medium · VYPR