#VU63588 Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-22785
Published: May 24, 2022
Zoom Workplace App for Android
Zoom Workplace App for iOS
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Workplace Desktop App for Windows
Zoom Video Communications, Inc.
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to Zoom client fails to properly constrain client session cookies to Zoom domains. A remote attacker can force unsuspecting users send Zoom-scoped session cookies to a non-Zoom domain and perform spoofing of a Zoom user.