Skip to content

DOM-based XSS/Content Spoofing via Prototype Pollution

Low
sawall published GHSA-6582-8v9q-v3fg Sep 15, 2021

Package

jitsi-meet (javascript)

Affected versions

< 2.0.6173

Patched versions

>= 2.0.6173

Description

Impact

Potential for client-side XSS via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability.

Patches

Fixes are in these PRs: #9320, #9404

Affects unstable versions of jitsi-meet prior to jitsi-meet_5991. Fixed by stable/jitsi-meet_6173

Workarounds

None.

References

This was initially reported via the 8x8 HackerOne vulnerability disclosure program at https://hackerone.com/8x8?type=team

Report link: https://hackerone.com/reports/1214493

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2021-39205

Weaknesses

No CWEs

Credits