In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
History

Wed, 30 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Jitsi
Jitsi meet
Weaknesses CWE-79
CPEs cpe:2.3:a:jitsi:meet:*:*:*:*:*:*:*:*
Vendors & Products Jitsi
Jitsi meet
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
Description In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-29T00:00:00

Updated: 2024-10-30T14:52:36.024Z

Reserved: 2024-08-19T00:00:00

Link: CVE-2024-44080

cve-icon Vulnrichment

Updated: 2024-10-30T14:52:30.504Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-29T22:15:03.633

Modified: 2024-11-01T12:57:35.843

Link: CVE-2024-44080

cve-icon Redhat

No data.