CVE-2020-25019

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
4.3
MEDIUM
Affected
1
PROJECT

Description

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

Jitsi Meet desktop application powered by :electron:
GitHubGitHub
1.62K