PT-2022-23596 · Jitsi · Jitsi

Published

2022-09-08

·

Updated

2024-08-03

·

CVE-2022-36736

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jitsi version 2.10.5550
Description The issue allows attackers to perform a clickjacking attack via a crafted HTTP request in the web UI. It is noted that this is disputed by the vendor.
Recommendations For Jitsi version 2.10.5550, as a temporary workaround, consider implementing additional security measures to prevent clickjacking attacks, such as using framebusting techniques or restricting access to sensitive areas of the web UI. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-36736

Affected Products

Jitsi