First published: Thu Feb 09 2023(Updated: )
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Jitsi Meet | <2022-09-14 | |
Microsoft Windows Operating System | ||
Jitsi Meet | <2022-09-14 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43550 is a command injection vulnerability in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 that allows an attacker to inject an arbitrary URL and potentially achieve remote execution.
CVE-2022-43550 has a severity rating of 9.8 (critical).
Jitsi versions prior to 2022-09-14 are affected by CVE-2022-43550.
To fix CVE-2022-43550, it is recommended to update Jitsi to commit 8aa7be58522f4264078d54752aae5483bfd854b2 or later.
CVE-2022-43550 is associated with CWE-77 (Command Injection) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).