---
title: Time To Update your Video Conference Software
description: At CSA, one of our most vital services is penetration testing. We exploit the vulnerabilities in devices and software (via means such as authentication bypass) to educate businesses on where weaknesses in their cybersecurity plans might exist.
image: https://csacyber.com/hubfs/Main-nav-images-4-min-555x312.png
---

[Skip to content](https://csacyber.com/blog/time-to-update-your-video-conference-software#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 April 11, 2023

 5 min read time

# Time To Update your Video Conference Software

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Penetration Testing](https://csacyber.com/blog/tag/penetration-testing) 

![](https://csacyber.com/hubfs/Main-nav-images-4-min-555x312.png)

### Jitsi-Meet Authentication Bypass (CVE-2021-33506)

At CSA, one of our most vital services is penetration testing. We exploit the vulnerabilities in devices and software (via means such as authentication bypass) to educate businesses on where weaknesses in their cybersecurity plans might exist. With this information, businesses can confidently invest in IT risk management software and adopt best practices that keep them covered.

One example of our penetration tests is this investigation into the Jitsi-Meet Authentication Bypass.

### What is Jitsi?

The way of working remotely changed drastically with COVID. Many products were quickly made available to fill the gap of meeting people face to face via the Internet using a webcam.

But there was a problem: most of these products were centralised, and all communications (chat, video, audio or file share) were travelling to and from the company’s servers.

To negate this issue, one product, in particular, gained a lot of attention: Jitsi, the open-source privacy-focused video chat with easy self-hosting capabilities.

With more than 300 contributors on GitHub, the project is proliferating and being used by many companies for private communications.

In this test, we examined exactly how Jitsi is vulnerable and how cyberattackers can assume moderator privileges in what should be a private call.

### TL;DR

The component jitsi-meet-prosody `(version <= 1.0.4985-1)` was shipped with an insecure default configuration in prosody.cfg.lua that allowed malicious unauthenticated users to gain moderator privileges before the start of a meeting.

### The Testing Environment

**Ubuntu 20.04.2 LTS**  
**jitsi-meet 2.0.5870-1**  
**jicofo 1.0-747-1**  
**jitsi-meet-web 1.0.4985-1**  
**jitsi-meet-web-config 1.0.4985-1**  
**jitsi-meet-prosody 1.0.4985-1**  
**jitsi-videobridge2 2.1-492-g5edaf7dd-1**

The configuration files were amended in accordance with the official documentation to enable authentication, therefore only moderators could start a new meeting.

### Attack Scenario

The use case for this authentication bypass is:

 1. A new meeting is scheduled, and the host sends out invites to participants.  
2. An attacker, part of the participant’s group, would receive a direct link to the meeting without any login details.  
3. Before the meeting starts, the attacker connects to the meeting and performs the authentication bypass, obtaining the moderator privileges before the real moderator.  
4. The real moderator connects and opens the room to all (other) participants.  
5. The attacker will keep having moderator privileges for the entire meeting, allowing complete control over other participants and the real moderator itself. It should be noted that a moderator cannot be “kicked” from a meeting once it has commenced.

 

### The Weak Default Configuration

The main muc component available at `“conference.yourdomain.ltd”` was missing the `‘restrict_room_creation’` directive, which allowed unauthenticated participants to force the conference to start and gain moderator privileges.

The pull request that fixed this issue can be seen at: [https://github.com/jitsi/jitsi-meet/pull/9252/files](https://github.com/jitsi/jitsi-meet/pull/9252/files)

### Jitsi-Meet Exploitation Walkthrough

When Jitsi is configured to require the host to log in, the following UI message is presented to the participants before the meeting can start:

![](https://surecloudcyber.com/assets/img/blog/FIGURE-1.png)  
Figure 1: Participant’s view while waiting for the host to join.

The XMPP BOSH requests and responses, while waiting for the host to open the room, are as follows:

![](https://surecloudcyber.com/assets/img/blog/FIGURE-2.png)  
Figure 2: Request made by the client

![](https://surecloudcyber.com/assets/img/blog/FIGURE-3.png)  
Figure 3: Response received by the server

The next step to trigger the vulnerability is to make the client (browser) believe that the server accepted its authentication request (which was never sent in the first place). This can be achieved by tampering with one of the “not authorised” responses to insert the following content:

![](https://surecloudcyber.com/assets/img/blog/FIGURE-3-1.png)

![](https://surecloudcyber.com/assets/img/blog/FIGURE-4.png)  
Figure 4: Image showing the intercepted server’s response and what was changed in the body

It is important to change the following elements to make a valid response:

- The `iq type` must be changed from `‘error’` to `‘result’`.
- The current room name must be specified under `‘room’` in the `conference` structure.

 

Also, this issue can only be triggered if the response from the server is tampered with in a timely manner. For this reason, it is strongly advised to let Burp Suite change the response via Match and Replace functionality:

![](https://surecloudcyber.com/assets/img/blog/FIGURE-5.png)  
Figure 5: Image showing Burp’s Match and Replace configuration

Let’s look at what’s happening in the requests/responses once the client receives the tampered response.

![](https://surecloudcyber.com/assets/img/blog/TABLE.jpg)  
Table 2: Client sends a structure, and Server assigns moderator privileges to the attacker.

At this stage, the attacker is the first one in the room; however, the room is still closed for all other participants. They need to wait for a moderator to log in to be able to see people joining the same space.

It should be noted that the attacker moderator does not have the necessary privileges to start the meeting – only the legitimate moderator can perform that action.

Once a legitimate moderator has joined, this will be the view from the attacker’s perspective:

![](https://surecloudcyber.com/assets/img/blog/FIGURE-6.png)

The attacker, having moderator role, can enable the lobby, set a room password, mute, stop video, chat, and generally perform all moderator actions.

![](https://surecloudcyber.com/assets/img/blog/FIGURE-7.png)![](https://surecloudcyber.com/assets/img/blog/FIGURE-8.png)![](https://surecloudcyber.com/assets/img/blog/FIGURE-9.png)

Please note: Moderators cannot kick out another moderator – which will make the attacker’s presence in the room permanent.

### What can be done to prevent Jitsi-meet takeover?

### The Countermeasure

Updating to the newly released version of Jitsi-meet-prosody will resolve this issue, which at the time of writing is 2.0.5963-1.

### Disclosure Timeline

 

- 20/05/2021: Bug Identified
- 21/05/2021: Technical documentation delivered to Jitsi developers privately, and CVE request submitted
- 21/05/2021: A fix is issued in the commit [https://github.com/jitsi/jitsi-meet/pull/9252/commits/5568dacf893116c8056f4aa1fea7baaf414d1947](https://github.com/jitsi/jitsi-meet/pull/9252/commits/5568dacf893116c8056f4aa1fea7baaf414d1947)
- 25/05/2021: Commit pushed into master branch
- 10/06/2021: New release of jitsi-meet-prosody
- 18/06/2021: Jitsi release advisory: [https://github.com/jitsi/security-advisories/blob/master/advisories/JSA-2021-0001.md](https://github.com/jitsi/security-advisories/blob/master/advisories/JSA-2021-0001.md%3C)
- 27/07/2021: Publishing this blog post

 

If you want to uncover vulnerabilities in your software or devices, look at our [penetration testing](https://csacyber.com/penetration-testing) services.

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-07T12:28:09.315Z",
  "datePublished" : "2023-04-11T04:00:00.000Z",
  "headline" : "Time To Update your Video Conference Software",
  "image" : [ "https://csacyber.com/hubfs/Main-nav-images-4-min-555x312.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/time-to-update-your-video-conference-software",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```