CVE-2024-44081

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.
Configurations

No configuration.

History

21 Nov 2024, 09:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-79

01 Nov 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) En Jitsi Meet anterior a 2.0.9779, la funcionalidad para compartir un archivo de video se implementó de manera insegura, lo que provocaba que los clientes cargaran videos desde una URL arbitraria si un mensaje de otro participante contenía una URL codificada en el formato esperado.

29 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 22:15

Updated : 2024-11-21 09:36


NVD link : CVE-2024-44081

Mitre link : CVE-2024-44081

CVE.ORG link : CVE-2024-44081


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')