CVE-2024-33530
Severity CVSS v4.0:
Pending analysis
Type:
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Publication date:
02/05/2024
Last modified:
20/03/2025
Description
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



