CVE-2021-22565
Summary
| CVE | CVE-2021-22565 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-09 13:15:00 UTC |
| Updated | 2022-10-25 16:20:00 UTC |
| Description | An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Exposure Notification Verification Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v1.1.2 · google/exposure-notifications-verification-server · GitHub | MISC | github.com | |
| Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server · Advisory · google/exposure-notifications-verification-server · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980123 Go (go) Security Update for github.com/google/exposure-notifications-verification-server (GHSA-wx8q-rgfr-cf6v)