PT-2017-16608 · Jitsi · Jitsi
Georg Lukas
·
Published
2017-02-09
·
Updated
2017-03-01
·
CVE-2017-5603
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jitsi versions 2.5.5061 through 2.9.5544
Description
The issue is related to an incorrect implementation of XEP-0280: Message Carbons in multiple XMPP clients, allowing a remote attacker to impersonate any user in the vulnerable application's display. This can lead to various kinds of social engineering attacks.
Recommendations
For Jitsi versions 2.5.5061 through 2.9.5544, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Origin Validation Error
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jitsi