CVE-2024-33850
MEDIUMDescription
Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.
Is your site exposed to CVE-2024-33850?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| pexip | pexip_infinity |
References
Frequently Asked Questions
What is CVE-2024-33850? +
How severe is CVE-2024-33850? +
What products are affected by CVE-2024-33850? +
How do I check if I'm vulnerable to CVE-2024-33850? +
Related Vulnerabilities
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used …
Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort …
Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a …
Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a …
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already …
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation …