Show plain JSON{"containers": {"cna": {"affected": [{"product": "Zoom Client for Meetings for Android", "vendor": "Zoom Video Communications Inc", "versions": [{"lessThan": "5.8.6", "status": "affected", "version": "unspecified", "versionType": "custom"}]}, {"product": "Zoom Client for Meetings for iOS", "vendor": "Zoom Video Communications Inc", "versions": [{"lessThan": "5.9.0", "status": "affected", "version": "unspecified", "versionType": "custom"}]}, {"product": "Zoom Client for Meetings for Linux", "vendor": "Zoom Video Communications Inc", "versions": [{"lessThan": "5.8.6", "status": "affected", "version": "unspecified", "versionType": "custom"}]}, {"product": "Zoom Client for Meetings for macOS", "vendor": "Zoom Video Communications Inc", "versions": [{"lessThan": "5.7.3", "status": "affected", "version": "unspecified", "versionType": "custom"}]}, {"product": "Zoom Client for Meetings for Windows", "vendor": "Zoom Video Communications Inc", "versions": [{"lessThan": "5.6.3", "status": "affected", "version": "unspecified", "versionType": "custom"}]}], "credits": [{"lang": "en", "value": "Johnny Yu of Walmart Global Tech"}], "datePublic": "2022-02-08T00:00:00", "descriptions": [{"lang": "en", "value": "The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources."}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.7, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L", "version": "3.1"}}], "problemTypes": [{"descriptions": [{"description": "Allocation of Resources Without Limits or Throttling", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2022-02-09T22:05:15", "orgId": "99b9af0d-a833-4a5d-9e2f-8b1324f35351", "shortName": "Zoom"}, "references": [{"tags": ["x_refsource_MISC"], "url": "https://explore.zoom.us/en/trust/security/security-bulletin"}], "source": {"discovery": "USER"}, "title": "Zoom Chat Susceptible to Zip Bombing", "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "security@zoom.us", "DATE_PUBLIC": "2022-02-08T12:00:00.000Z", "ID": "CVE-2022-22780", "STATE": "PUBLIC", "TITLE": "Zoom Chat Susceptible to Zip Bombing"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "Zoom Client for Meetings for Android", "version": {"version_data": [{"version_affected": "<", "version_value": "5.8.6"}]}}, {"product_name": "Zoom Client for Meetings for iOS", "version": {"version_data": [{"version_affected": "<", "version_value": "5.9.0"}]}}, {"product_name": "Zoom Client for Meetings for Linux", "version": {"version_data": [{"version_affected": "<", "version_value": "5.8.6"}]}}, {"product_name": "Zoom Client for Meetings for macOS", "version": {"version_data": [{"version_affected": "<", "version_value": "5.7.3"}]}}, {"product_name": "Zoom Client for Meetings for Windows", "version": {"version_data": [{"version_affected": "<", "version_value": "5.6.3"}]}}]}, "vendor_name": "Zoom Video Communications Inc"}]}}, "credit": [{"lang": "eng", "value": "Johnny Yu of Walmart Global Tech"}], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources."}]}, "impact": {"cvss": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.7, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L", "version": "3.1"}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "Allocation of Resources Without Limits or Throttling"}]}]}, "references": {"reference_data": [{"name": "https://explore.zoom.us/en/trust/security/security-bulletin", "refsource": "MISC", "url": "https://explore.zoom.us/en/trust/security/security-bulletin"}]}, "source": {"discovery": "USER"}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T03:21:49.147Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://explore.zoom.us/en/trust/security/security-bulletin"}]}]}, "cveMetadata": {"assignerOrgId": "99b9af0d-a833-4a5d-9e2f-8b1324f35351", "assignerShortName": "Zoom", "cveId": "CVE-2022-22780", "datePublished": "2022-02-09T22:05:15.893138Z", "dateReserved": "2022-01-07T00:00:00", "dateUpdated": "2024-09-16T21:04:27.677Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}