MEDIUM · 4.7

CVE-2021-34425

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In vers...

Vulnerability Description

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "link preview" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ZoomMeetings< 5.7.3
AppleIphone Os-
AppleMacos-
GoogleAndroid-
LinuxLinux Kernel-
MicrosoftWindows-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-34425?

CVE-2021-34425 is a vulnerability with a CVSS score of 4.7 (MEDIUM). The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In vers...

How severe is CVE-2021-34425?

CVE-2021-34425 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-34425?

Check the references section above for vendor advisories and patch information. Affected products include: Zoom Meetings, Apple Iphone Os, Apple Macos, Google Android, Linux Linux Kernel.