CVE-2021-39205
DOM-based XSS/Content Spoofing via Prototype Pollution
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- August 16, 2021
- Published Date
- September 15, 2021
- Last Updated
- August 04, 2024
- Vendor
- jitsi
- Product
- jitsi-meet
- Description
- Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is fixed in Jitsi Meet version 2.0.6173. There are no known workarounds aside from upgrading.
CVSS Scores
CVSS v3.1
6.8 - MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploit Status
- Exploited in the Wild
- Yes (2021-09-15 17:15:12 UTC) Source
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CVE | 2021-09-15 17:15:12 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel