jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-08-29T16:07:29

Updated: 2024-08-04T15:26:09.339Z

Reserved: 2020-08-29T00:00:00

Link: CVE-2020-25019

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-08-29T17:15:11.297

Modified: 2020-09-03T17:58:32.627

Link: CVE-2020-25019

cve-icon Redhat

No data.