Client-Side Enforcement of Server-Side Security
CVE-2023-39218
Summary
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- HIGH
- HIGH
- NONE
CWE-602 - Client-Side Enforcement of Server-Side Security
The software is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
References
Advisory Timeline
- Published