NixOS / nixpkgs

Nix Packages collection & NixOS
MIT License
18.38k stars 14.33k forks source link

Vulnerability roundup 107: jitsi-meet-1.0.5307: 1 advisory [6.1] #142978

Closed ckauhaus closed 3 years ago

ckauhaus commented 3 years ago

search, files

CVE details

CVE-2021-39205

Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is fixed in Jitsi Meet version 2.0.6173. There are no known workarounds aside from upgrading.


Scanned versions: nixos-21.05: 3b1789322fc.

Cc @mmilata Cc @petabyteboy Cc @ryantm

dpausp commented 3 years ago

Problem like in #138676, it's for a different package. We are not affected as our version is newer.