The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will take place.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: HCL

Published: 2022-04-15T00:00:00

Updated: 2022-05-12T21:25:25

Reserved: 2021-02-26T00:00:00


Link: CVE-2021-27770

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-12T22:15:11.823

Modified: 2023-06-30T21:26:36.650


Link: CVE-2021-27770

JSON object: View

cve-icon Redhat Information

No data.