CVE编号
CVE-2021-34418利用情况
暂无补丁情况
N/A披露时间
2021-11-12漏洞描述
The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
https://explore.zoom.us/en/trust/security/security-bulletin |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | zoom | zoom_on-premise_meeting_connector_controller | * |
Up to (excluding) 4.6.239.20200613 |
|||||
运行在以下环境 | |||||||||
应用 | zoom | zoom_on-premise_meeting_connector_mmr | * |
Up to (excluding) 4.6.239.20200613 |
|||||
运行在以下环境 | |||||||||
应用 | zoom | zoom_on-premise_recording_connector | * |
Up to (excluding) 3.8.42.20200905 |
|||||
运行在以下环境 | |||||||||
应用 | zoom | zoom_on-premise_virtual_room_connector | * |
Up to (excluding) 4.4.6344.20200612 |
|||||
运行在以下环境 | |||||||||
应用 | zoom | zoom_on-premise_virtual_room_connector_load_balancer | * |
Up to (excluding) 2.5.5492.20200616 |
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 无
- 影响范围 未更改
- 用户交互 无
- 可用性 低
- 保密性 无
- 完整性 无
还没有评论,来说两句吧...