First published: Tue Oct 29 2024(Updated: )
In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jitsi Meet | <2.0.9779 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44081 is classified as a high severity vulnerability due to its potential to allow unauthorized video file sharing.
To fix CVE-2024-44081, upgrade Jitsi Meet to version 2.0.9779 or later.
CVE-2024-44081 affects Jitsi Meet versions prior to 2.0.9779.
CVE-2024-44081 can compromise user privacy by allowing clients to load video files from arbitrary URLs provided by other participants.
As of now, there is no public information indicating that CVE-2024-44081 is being actively exploited in the wild.