Unknown · Jitsi Meet · CVE-2021-39215
**Name of the Vulnerable Software and Affected Versions**
Jitsi Meet versions prior to 2.0.5963
**Description**
Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected rooms.
**Recommendations**
For versions prior to 2.0.5963, update to Jitsi Meet 2.0.5963 to resolve the issue. As a temporary workaround, consider restricting access to protected rooms until the update is applied.