What the vulnerability does
01Description
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
Explanation of Vulnerability in Simple Terms
Vimeo versions up to 1.2.2 leak sensitive information in outbound network traffic. An attacker on the network path between the site and Vimeo's servers can intercept and read data that should remain private. No authentication or user interaction is required to exploit this vulnerability.
What an attacker can do
Read sensitive data transmitted by the site to Vimeo's servers.
Potential impact on your site
Sensitive information may be exposed to network eavesdroppers if traffic is not encrypted.
Conditions required to exploit
Network access to intercept traffic between the site and Vimeo.
Key dates
External resources
Related vulnerabilities