The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will take place.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2022-05-12T21:25:25.427594Z

Updated: 2024-09-16T20:02:52.780Z

Reserved: 2021-02-26T00:00:00

Link: CVE-2021-27770

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-12T22:15:11.823

Modified: 2023-06-30T21:26:36.650

Link: CVE-2021-27770

cve-icon Redhat

No data.