PT-2020-15894 · Jitsi · Jitsi-Meet-Electron

Malamala

·

Published

2020-07-01

·

Updated

2020-09-03

·

CVE-2020-25019

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions jitsi-meet-electron versions prior to 2.3.0
Description The issue arises when the Electron shell.openExternal function is called without verifying that the URL is for an http or https resource, under certain circumstances.
Recommendations For versions prior to 2.3.0, update to version 2.3.0 or later to resolve the issue.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14719
CVE-2020-25019
GHSA-X4H8-FHRP-PM3P

Affected Products

Jitsi-Meet-Electron