VYPR

Jitsi

by Jitsi

Source repositories

CVEs (6)

  • CVE-2024-44080HigOct 29, 2024
    risk 0.49cvss 7.5epss 0.01

    In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.

  • CVE-2024-33530HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

  • CVE-2022-36736MedSep 8, 2022
    risk 0.40cvss 6.1epss 0.01

    Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking attack via a crafted HTTP request. NOTE: this is disputed by the vendor

  • CVE-2017-5603MedFeb 9, 2017
    risk 0.38cvss 5.9epss 0.02

    An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Jitsi…

  • CVE-2022-43550CriFeb 9, 2023
    risk 0.00cvss 9.8epss 0.02

    A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.

  • CVE-2021-39205MedSep 15, 2021
    risk 0.00cvss 6.8epss 0.01

    Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being…