PT-2021-22457 · Unknown · Jitsi Meet

Damencho

+1

·

Published

2021-09-15

·

Updated

2022-09-10

·

CVE-2021-39205

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jitsi Meet versions prior to 2.0.6173
Description Jitsi Meet is an open source video conferencing application. The issue arises from client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild.
Recommendations For versions prior to 2.0.6173, upgrade to version 2.0.6173 to resolve the issue. At the moment, there is no information about other workarounds aside from upgrading.

Fix

Prototype Pollution

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-39205
GHSA-6582-8V9Q-V3FG

Affected Products

Jitsi Meet