The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published: 2022-05-18T15:42:19.156563Z

Updated: 2024-09-17T02:41:15.335Z

Reserved: 2022-01-07T00:00:00

Link: CVE-2022-22785

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-18T16:15:08.697

Modified: 2022-05-27T16:13:16.927

Link: CVE-2022-22785

cve-icon Redhat

No data.