CVE-2020-11878
CRITICALJitsi Meet < stable-4384-1 - Use of Hard-coded Credentials
Title source: llmDescription
The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/jitsi/docker-jitsi-meet/compare/stable-4384...stable-4384-1
Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/jitsi/docker-jitsi-meet/blob/master/CHANGELOG.md#stable-4384-1
Scores
CVSS v3
9.8
EPSS
0.0132
EPSS Percentile
67.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (1)
jitsi/meet
< stable-4384-1
Published
Apr 17, 2020
Tracked Since
Feb 18, 2026