
Cloud Vulnerability DB
A community-led vulnerabilities database
A disputed vulnerability was identified in Jitsi-2.10.5550's web UI, tracked as CVE-2022-36736. The vulnerability allegedly allows attackers to perform clickjacking attacks through crafted HTTP requests. The vendor has disputed this vulnerability claim (CVE List).
The vulnerability is reportedly related to insufficient input validation of iFrame data in HTTP requests sent to the affected application. The issue specifically concerns the web UI component of Jitsi Meet, where the application may not properly restrict rendered UI layers or frames (GitHub POC).
If successfully exploited, the vulnerability could potentially allow an attacker to perform clickjacking attacks where users are tricked into clicking malicious links, affecting the integrity of the device. The attack can be executed by an unauthenticated, remote attacker (GitHub POC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."