NixOS / nixpkgs

Nix Packages collection & NixOS
MIT License
18.38k stars 14.33k forks source link

Vulnerability roundup 107: jitsi-meet-1.0.5415: 1 advisory [6.1] #142979

Closed ckauhaus closed 3 years ago

ckauhaus commented 3 years ago

search, files

CVE details

CVE-2021-39205

Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is fixed in Jitsi Meet version 2.0.6173. There are no known workarounds aside from upgrading.


Scanned versions: nixos-unstable: 34ad3ffe08a.

Cc @petabyteboy Cc @ryantm Cc @yu-re-ka

dpausp commented 3 years ago

Problem like in https://github.com/NixOS/nixpkgs/issues/138676, it's for a different package. We are not affected as our version is newer.

dpausp commented 3 years ago

@ckauhaus please whitelist this CVE

ckauhaus commented 3 years ago

done