CVE-2021-39215

HIGH

Jitsi Meet < 2.0.5963 - Improper Authentication via Symmetrical JWT Validation

Title source: llm
STIX 2.1

Description

Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected rooms. This issue is fixed in Jitsi Meet 2.0.5963. There are no known workarounds aside from updating.

References (2)

Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/jitsi/jitsi-meet/pull/9319

Scores

CVSS v3 7.5
EPSS 0.0120
EPSS Percentile 64.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (1)
8x8/jitsi_meet 2.0.5963
Published Sep 15, 2021
Tracked Since Feb 18, 2026