CVE-2021-33839
Summary
| CVE | CVE-2021-33839 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-04 00:15:00 UTC |
| Updated | 2021-06-07 18:08:00 UTC |
| Description | Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Patrick Hennig Twitterissä: "Du hast eine Location in ein privates Meeting umgewandelt ... beim privaten Treffen wird der Name geteilt ... dass muss der Gast aber beim CheckIn bestätigen ... das hast du schon gesehen oder?… https://t.co/KmuNPo00CT" | MISC | twitter.com | |
| misc/luca_traceIds.md at master · mame82/misc · GitHub | MISC | github.com | |
| 11 Luca Location Betreiber manipuliert QR code um an Nutzerdaten zu kommen - YouTube | MISC | youtu.be | |
| Security Objectives — Security Overview | MISC | luca-app.de | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.