Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgwf-5fwc-xx64

Опубликовано: 30 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.

In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.

EPSS

Процентиль: 44%
0.00534
Низкий

7.5 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.

CVSS3: 7.5
debian
почти 2 года назад

In Jitsi Meet before 2.0.9779, the functionality to share an image usi ...

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость функции обмена изображениями программного обеспечения для проведения видеоконференций Jitsi Meet, позволяющая нарушителю загружать произвольные GIF-файлы

EPSS

Процентиль: 44%
0.00534
Низкий

7.5 High

CVSS3

Дефекты

CWE-79