Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2hj-224j-7m2q

Опубликовано: 30 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.

EPSS

Процентиль: 55%
0.00326
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.

CVSS3: 9.8
debian
больше 1 года назад

In Jitsi Meet before 2.0.9779, the functionality to share a video file ...

CVSS3: 9.8
fstec
больше 1 года назад

Уязвимость функции обмена видеофайлами программного обеспечения для проведения видеоконференций Jitsi Meet, позволяющая нарушителю загружать произвольные видеофайлы

EPSS

Процентиль: 55%
0.00326
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-79