PT-2017-16608 · Jitsi · Jitsi
Georg Lukas
·
Publicado
2017-02-09
·
Atualizado
2017-03-01
·
CVE-2017-5603
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jitsi versions 2.5.5061 through 2.9.5544
Description
The issue is related to an incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients, allowing a remote attacker to impersonate any user in the vulnerable application's display. This can lead to various kinds of social engineering attacks.
Recommendations
For Jitsi versions 2.5.5061 through 2.9.5544, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Origin Validation Error
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jitsi