CVE-2022-43550
CRITICALJitsi <8aa7be58522f4264078d54752aae5483bfd854b2 - Command Injection
Title source: llmDescription
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.
References (1)
Core 1
Scores
CVSS v3
9.8
EPSS
0.0179
EPSS Percentile
75.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-77
CWE-78
Status
published
Products (1)
jitsi/jitsi
< 2022-09-14
Published
Feb 09, 2023
Tracked Since
Feb 18, 2026