The Zoom Client for Meetings (for Android, iOS, Linux,...
Low severity
Unreviewed
Published
Nov 15, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Nov 14, 2022
Published to the GitHub Advisory Database
Nov 15, 2022
Last updated
Jan 28, 2023
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.
References