First published: Tue Oct 29 2024(Updated: )
In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
8x8 Jitsi Meet | <2.0.9779 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44080 has been classified as a moderate-severity vulnerability.
To fix CVE-2024-44080, upgrade Jitsi Meet to version 2.0.9779 or later.
CVE-2024-44080 affects all versions of Jitsi Meet prior to 2.0.9779.
CVE-2024-44080 allows arbitrary loading of GIFs from misleading URLs sent in messages.
CVE-2024-44080 was disclosed alongside the release of the fix in the updates for Jitsi Meet.