Jitsi: Bridge Message Spoofing due to Improper JSON Handling leads to Prototype Pollution

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

Jitsi: Bridge Message Spoofing due to Improper JSON Handling leads to Prototype Pollution

Post by Shane1145 »

The Jitsi VideoBridge failed to properly handle JSON messages with duplicate colibriClass keys, enabling clients to send messages interpreted differently by the bridge and resulting in unauthorized actions within video conferences.
Jitsi Security Advisory has been published:

https://hackerone.com/reports/2095061
Post Reply