ZeroHour

CVE-2020-25019

PoC
CVSS 3.1
7.5 high
EPSS
1%p62
Published
()
Modified
Description

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

Vendors
jitsi
Products
meet electron
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.