Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Aaronkvanmeerten

#37531of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2021-22467
7.5
2021-09-15
Unknown · Jitsi Meet · CVE-2021-39215
**Name of the Vulnerable Software and Affected Versions** Jitsi Meet versions prior to 2.0.5963 **Description** Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected rooms. **Recommendations** For versions prior to 2.0.5963, update to Jitsi Meet 2.0.5963 to resolve the issue. As a temporary workaround, consider restricting access to protected rooms until the update is applied.