Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aaronkvanmeerten

#37693of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2021-22467
7.5
2021-09-15
Unknown · Jitsi Meet · CVE-2021-39215
**Name of the Vulnerable Software and Affected Versions** Jitsi Meet versions prior to 2.0.5963 **Description** Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected rooms. **Recommendations** For versions prior to 2.0.5963, update to Jitsi Meet 2.0.5963 to resolve the issue. As a temporary workaround, consider restricting access to protected rooms until the update is applied.