CVE-2021-21301

Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in version 3.75.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wire:wire:*:*:*:*:*:iphone_os:*:*

History

21 Nov 2024, 05:47

Type Values Removed Values Added
References () https://github.com/wireapp/wire-ios/commit/7e3c30120066c9b10e50cc0d20012d0849c33a40 - Patch, Third Party Advisory () https://github.com/wireapp/wire-ios/commit/7e3c30120066c9b10e50cc0d20012d0849c33a40 - Patch, Third Party Advisory
References () https://github.com/wireapp/wire-ios/pull/4879 - Patch, Third Party Advisory () https://github.com/wireapp/wire-ios/pull/4879 - Patch, Third Party Advisory
References () https://github.com/wireapp/wire-ios/security/advisories/GHSA-7fg4-x8vj-qvxf - Patch, Third Party Advisory () https://github.com/wireapp/wire-ios/security/advisories/GHSA-7fg4-x8vj-qvxf - Patch, Third Party Advisory
CVSS v2 : 4.3
v3 : 4.3
v2 : 4.3
v3 : 2.6

Information

Published : 2021-02-11 18:15

Updated : 2024-11-21 05:47


NVD link : CVE-2021-21301

Mitre link : CVE-2021-21301

CVE.ORG link : CVE-2021-21301


JSON object : View

Products Affected

wire

  • wire
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor