PT-2021-22457 · Unknown · Jitsi Meet
Damencho
+1
·
Published
2021-09-15
·
Updated
2022-09-10
·
CVE-2021-39205
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jitsi Meet versions prior to 2.0.6173
Description
Jitsi Meet is an open source video conferencing application. The issue arises from client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild.
Recommendations
For versions prior to 2.0.6173, upgrade to version 2.0.6173 to resolve the issue.
At the moment, there is no information about other workarounds aside from upgrading.
Fix
Prototype Pollution
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jitsi Meet