Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8737-w627-mrv7

Опубликовано: 15 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat’s “link preview” functionality. In versions prior to 5.7.3, if a user were to enable the chat’s “link preview” feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat’s “link preview” functionality. In versions prior to 5.7.3, if a user were to enable the chat’s “link preview” feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.

EPSS

Процентиль: 48%
0.0025
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.7
nvd
около 4 лет назад

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "link preview" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.

EPSS

Процентиль: 48%
0.0025
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-918