Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5jg-c28r-h22h

Опубликовано: 19 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

EPSS

Процентиль: 40%
0.00182
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 5.9
nvd
больше 3 лет назад

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

CVSS3: 5.9
fstec
около 4 лет назад

Уязвимость клиента для проведения аудио- и видеоконференций в режиме реального времени Zoom Client for Meetings для Android, iOS, Linux, macOS и Windows, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 40%
0.00182
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-565