In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.