PT-2024-25509 · Pexip · Pexip Infinity
Published
2024-06-10
·
Updated
2025-06-20
·
CVE-2024-33850
CVSS v3.1
4.3
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Pexip Infinity versions prior to 34.1
Description
The issue concerns improper access control, allowing individuals in a waiting room to view the conference roster list and perform certain actions before being admitted to the meeting.
Recommendations
For versions prior to 34.1, update to version 34.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the conference roster list and limiting actions that can be performed by individuals in the waiting room until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pexip Infinity