jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-17718 | jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-17T19:13:58.652Z
Reserved: 2020-08-29T00:00:00.000Z
Link: CVE-2020-25019
No data.
Status : Modified
Published: 2020-08-29T17:15:11.297
Modified: 2025-11-17T20:15:49.057
Link: CVE-2020-25019
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD