First published: Thu Feb 09 2017(Updated: )
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Jitsi 2.5.5061 - 2.9.5544.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jitsi Meet | =2.5.5061 | |
Jitsi Meet | =2.9.5544 | |
=2.5.5061 | ||
=2.9.5544 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5603 is considered to have medium severity due to the potential for social engineering attacks.
To fix CVE-2017-5603, upgrade Jitsi to the latest version that addresses this vulnerability.
Jitsi versions 2.5.5061 to 2.9.5544 are affected by CVE-2017-5603.
CVE-2017-5603 is a vulnerability related to incorrect implementation of message handling in XMPP clients.
An attacker can impersonate any user in the application, potentially leading to various social engineering attacks.