PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5603 Jitsi CVE debrief

CVE-2017-5603 is a medium-severity Jitsi vulnerability tied to incorrect handling of XEP-0280 Message Carbons. In affected versions, a remote attacker could cause the application to display messages as if they came from another user, including a contact, creating a practical social-engineering risk rather than a code-execution issue.

Vendor
Jitsi
Product
Unknown
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-09
Original CVE updated
2026-05-13
Advisory published
2017-02-09
Advisory updated
2026-05-13

Who should care

Jitsi administrators, helpdesk teams, and users of Jitsi 2.5.5061 through 2.9.5544 should care. Any environment that relies on chat identity for trust decisions, approvals, or incident response should treat this as a spoofing and impersonation risk.

Technical summary

The NVD record describes a network-reachable issue with no privileges and no user interaction required, but with high attack complexity. The flaw is an incorrect implementation of XEP-0280 Message Carbons that can let an attacker influence how message origin is presented in the client UI. NVD maps the issue to integrity impact only (CVSS v3.0 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N) and lists CWE-20 and CWE-346.

Defensive priority

Medium. The main impact is message impersonation and trust abuse, which can support phishing or fraud inside chat workflows, but the CVE does not indicate confidentiality or availability impact.

Recommended defensive actions

  • Confirm whether any Jitsi deployments are within the affected range 2.5.5061-2.9.5544.
  • Upgrade to a Jitsi release that is outside the affected range or otherwise contains the vendor fix.
  • If you maintain a custom build, review the referenced Jitsi patch commit and ensure the Message Carbons handling matches the intended validation behavior.
  • Treat unexpected identity changes in chat as a security signal; reinforce out-of-band verification for approvals, credential requests, and other trust-sensitive messages.

Evidence notes

The CVE description states that an incorrect implementation of XEP-0280 Message Carbons can allow a remote attacker to impersonate users in the application's display, enabling social engineering. The NVD record identifies affected Jitsi versions 2.5.5061 through 2.9.5544 and assigns CVSS v3.0 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N with CWE-20 and CWE-346. The source references include a Jitsi patch commit and contemporaneous advisories discussing the issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5603 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5603

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5603 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5603

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.