CVE-2020-25019

HIGH

Jitsi Meet Electron < 2.3.0 - Data Authenticity Bypass

Title source: rule
STIX 2.1

Description

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-345
Status published
Products (1)
jitsi/meet_electron < 2.3.0
Published Aug 29, 2020
Tracked Since Feb 18, 2026