CVE-2024-44080

In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
Configurations

No configuration.

History

30 Oct 2024, 15:35

Type Values Removed Values Added
Summary
  • (es) En Jitsi Meet anterior a 2.0.9779, la funcionalidad para compartir una imagen usando giphy se implementó de manera insegura, lo que provocaba que los clientes cargaran GIF desde cualquier URL arbitraria si un mensaje de otro participante contenía una URL codificada en el formato esperado.
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

29 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 22:15

Updated : 2024-10-30 15:35


NVD link : CVE-2024-44080

Mitre link : CVE-2024-44080

CVE.ORG link : CVE-2024-44080


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')