In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00083}

epss

{'score': 0.00128}


Thu, 10 Jul 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared 8x8
8x8 jitsi Meet
CPEs cpe:2.3:a:8x8:jitsi_meet:*:*:*:*:*:*:*:*
Vendors & Products 8x8
8x8 jitsi Meet

Wed, 30 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Jitsi
Jitsi meet
Weaknesses CWE-79
CPEs cpe:2.3:a:jitsi:meet:*:*:*:*:*:*:*:*
Vendors & Products Jitsi
Jitsi meet
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
Description In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-29T00:00:00

Updated: 2024-10-30T14:52:36.024Z

Reserved: 2024-08-19T00:00:00

Link: CVE-2024-44080

cve-icon Vulnrichment

Updated: 2024-10-30T14:52:30.504Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-29T22:15:03.633

Modified: 2025-07-10T19:33:11.537

Link: CVE-2024-44080

cve-icon Redhat

No data.