{"api_version":"1","generated_at":"2026-07-23T18:48:00+00:00","cve":"CVE-2021-33839","urls":{"html":"https://cve.report/CVE-2021-33839","api":"https://cve.report/api/cve/CVE-2021-33839.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-33839","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-33839"},"summary":{"title":"CVE-2021-33839","description":"Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-06-04 00:15:00","updated_at":"2021-06-07 18:08:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://twitter.com/patrick_hennig/status/1387738281757061125","name":"https://twitter.com/patrick_hennig/status/1387738281757061125","refsource":"MISC","tags":[],"title":"Patrick Hennig Twitterissä: \"Du hast eine Location in ein privates Meeting umgewandelt ... beim privaten Treffen wird der Name geteilt ... dass muss der Gast aber beim CheckIn bestätigen ... das hast du schon gesehen oder?… https://t.co/KmuNPo00CT\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/mame82/misc/blob/master/luca_traceIds.md","name":"https://github.com/mame82/misc/blob/master/luca_traceIds.md","refsource":"MISC","tags":[],"title":"misc/luca_traceIds.md at master · mame82/misc · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://youtu.be/jWyDfEB0m08","name":"https://youtu.be/jWyDfEB0m08","refsource":"MISC","tags":[],"title":"11 Luca Location Betreiber manipuliert QR code um an Nutzerdaten zu kommen - YouTube","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://luca-app.de/securityoverview/properties/objectives.html","name":"https://luca-app.de/securityoverview/properties/objectives.html","refsource":"MISC","tags":[],"title":"Security Objectives — Security Overview","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-33839","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33839","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"33839","vulnerable":"1","versionEndIncluding":"1.7.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"luca-app","cpe5":"luca","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-33839","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/mame82/misc/blob/master/luca_traceIds.md","refsource":"MISC","name":"https://github.com/mame82/misc/blob/master/luca_traceIds.md"},{"url":"https://luca-app.de/securityoverview/properties/objectives.html","refsource":"MISC","name":"https://luca-app.de/securityoverview/properties/objectives.html"},{"url":"https://youtu.be/jWyDfEB0m08","refsource":"MISC","name":"https://youtu.be/jWyDfEB0m08"},{"url":"https://twitter.com/patrick_hennig/status/1387738281757061125","refsource":"MISC","name":"https://twitter.com/patrick_hennig/status/1387738281757061125"}]}},"nvd":{"publishedDate":"2021-06-04 00:15:00","lastModifiedDate":"2021-06-07 18:08:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:luca-app:luca:*:*:*:*:*:android:*:*","versionEndIncluding":"1.7.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"33839","Ordinal":"209279","Title":"CVE-2021-33839","CVE":"CVE-2021-33839","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"33839","Ordinal":"1","NoteData":"Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"33839","Ordinal":"2","NoteData":"2021-06-03","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"33839","Ordinal":"3","NoteData":"2021-06-03","Type":"Other","Title":"Modified"}]}}}