External URL Handling Flaw in Jitsi Meet Electron
CVE-2020-25019
7.5HIGH
What is CVE-2020-25019?
Jitsi Meet Electron versions before 2.3.0 possess a vulnerability that arises when the application invokes the Electron shell.openExternal function without validating the target URL. This lack of validation can potentially allow attackers to exploit the flaw by redirecting users to malicious URLs, posing significant security risks. Users are strongly advised to upgrade to version 2.3.0 or later to mitigate this risk.
