Description
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2409 | An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater. |
Github GHSA |
GHSA-wx8q-rgfr-cf6v | Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server |
References
History
No history.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-09-16T17:53:56.557Z
Reserved: 2021-01-05T00:00:00.000Z
Link: CVE-2021-22565
No data.
Status : Modified
Published: 2021-12-09T13:15:08.767
Modified: 2024-11-21T05:50:20.070
Link: CVE-2021-22565
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA