{ "schema_version": "1.4.0", "id": "GHSA-qq47-rh4x-g9mg", "modified": "2022-05-24T19:20:36Z", "published": "2022-05-24T19:20:36Z", "aliases": [ "CVE-2021-34417" ], "details": "The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34417" }, { "type": "WEB", "url": "https://explore.zoom.us/en/trust/security/security-bulletin" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-11-11T23:15:00Z" } }