PT-2024-25509 · Pexip · Pexip Infinity

Published

2024-06-10

·

Updated

2025-06-20

·

CVE-2024-33850

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Pexip Infinity versions prior to 34.1
Description The issue concerns improper access control, allowing individuals in a waiting room to view the conference roster list and perform certain actions before being admitted to the meeting.
Recommendations For versions prior to 34.1, update to version 34.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the conference roster list and limiting actions that can be performed by individuals in the waiting room until the update is applied.

Fix

Related Identifiers

CVE-2024-33850

Affected Products

Pexip Infinity