CVE-2022-43550 is a critical command injection vulnerability affecting Jitsi versions prior to commit 8aa7be58522f4264078d54752aae5483bfd854b1 when launching browsers on Windows. This flaw allows an unauthenticated attacker to inject arbitrary URLs, potentially leading to remote code execution with a CVSS score of 9.8 (Critical). While no public exploit code or active exploitation has been observed, its high severity and straightforward attack vector (AV:N/AC:L/PR:N/UI:N) warrant immediate patching. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022-09-14CPE matchmatch criteria | cpe:2.3:a:jitsi:jitsi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.