PT-2022-23596 · Jitsi · Jitsi
Published
2022-09-08
·
Updated
2024-08-03
·
CVE-2022-36736
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jitsi version 2.10.5550
Description
The issue allows attackers to perform a clickjacking attack via a crafted HTTP request in the web UI. It is noted that this is disputed by the vendor.
Recommendations
For Jitsi version 2.10.5550, as a temporary workaround, consider implementing additional security measures to prevent clickjacking attacks, such as using framebusting techniques or restricting access to sensitive areas of the web UI. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jitsi