CVE-2024-44081: 8x8 Jitsi Meet
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.
Affected products
- 8x8 Jitsi Meet: before 2.0.9779 (fixed in 2.0.9779)
Published 2024-10-29. Last modified 2026-06-17.