Логотип exploitDog
bind:CVE-2022-22785
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-22785

Количество 3

Количество 3

nvd логотип

CVE-2022-22785

больше 3 лет назад

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-x5jg-c28r-h22h

больше 3 лет назад

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2022-03944

около 4 лет назад

Уязвимость клиента для проведения аудио- и видеоконференций в режиме реального времени Zoom Client for Meetings для Android, iOS, Linux, macOS и Windows, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-22785

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-x5jg-c28r-h22h

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-03944

Уязвимость клиента для проведения аудио- и видеоконференций в режиме реального времени Zoom Client for Meetings для Android, iOS, Linux, macOS и Windows, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.9
0%
Низкий
около 4 лет назад

Уязвимостей на страницу