Loading HuntDB...

GHSA-x5jg-c28r-h22h

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

Related CVEs

Key Information

GHSA ID
GHSA-x5jg-c28r-h22h
Published
May 19, 2022 12:00 AM
Last Modified
May 28, 2022 12:00 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.