CVE-2021-39205
Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped.
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is fixed in Jitsi Meet version 2.0.6173. There are no known workarounds aside from upgrading.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-1321
- Affected
- 8x8/jitsi meet
- Source
- security-advisories@github.com
References
- https://github.com/jitsi/jitsi-meet/pull/9320Patch, Third Party Advisory
- https://github.com/jitsi/jitsi-meet/pull/9404Patch, Third Party Advisory
- https://github.com/jitsi/jitsi-meet/security/advisories/GHSA-6582-8v9q-v3fgThird Party Advisory
- https://hackerone.com/reports/1214493Permissions Required
- https://github.com/jitsi/jitsi-meet/pull/9320Patch, Third Party Advisory
- https://github.com/jitsi/jitsi-meet/pull/9404Patch, Third Party Advisory
- https://github.com/jitsi/jitsi-meet/security/advisories/GHSA-6582-8v9q-v3fgThird Party Advisory
- https://hackerone.com/reports/1214493Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.