CVE-2021-22565

An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:exposure_notification_verification_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:50

Type Values Removed Values Added
References () https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2 - Patch, Release Notes, Third Party Advisory () https://github.com/google/exposure-notifications-verification-server/releases/tag/v1.1.2 - Patch, Release Notes, Third Party Advisory
References () https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v - Third Party Advisory () https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-wx8q-rgfr-cf6v - Third Party Advisory

Information

Published : 2021-12-09 13:15

Updated : 2024-11-21 05:50


NVD link : CVE-2021-22565

Mitre link : CVE-2021-22565

CVE.ORG link : CVE-2021-22565


JSON object : View

Products Affected

google

  • exposure_notification_verification_server
CWE
CWE-284

Improper Access Control

NVD-CWE-Other