Vendors8x8jitsi_meetall versions
Vulnerabilities

8x8 Jitsi Meet

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-44081
In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.
Published 2024-10-29 · Analyzed
9.8EPSS 0.007
CVE-2021-39215
Authentication Bypass: Forged Tokens Allow Access to Arbitrary Rooms
Published 2021-09-15 · Modified
7.5EPSS 0.012
CVE-2021-33506
jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circumvent conference moderation.
Published 2021-05-26 · Modified
7.5EPSS 0.012
CVE-2024-44080
In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
Published 2024-10-29 · Analyzed
7.5EPSS 0.005
CVE-2021-39205
DOM-based XSS/Content Spoofing via Prototype Pollution
Published 2021-09-15 · Modified
6.8EPSS 0.012