Insecure GIF Sharing in Jitsi Meet Prior to v2.0.9779
CVE-2024-44080

7.5HIGH

Key Information:

Vendor

Jitsi Meet

Vendor
CVE Published:
29 October 2024

What is CVE-2024-44080?

A security flaw in Jitsi Meet before version 2.0.9779 enables participants to exploit image sharing functionality. The system permits clients to load GIFs from arbitrary URLs, introducing risks as any malicious participant could send a URL encoded in the expected format. This vulnerability can lead to unintended content being displayed, potentially harming users' security and privacy.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.