CVE-2021-22565

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-22565
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22565.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-22565
Aliases
Published
2021-12-09T13:15:08Z
Modified
2024-08-21T14:57:04.376420Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
[none]
Details

An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.

References

Affected packages

Git / github.com/google/exposure-notifications-verification-server

Affected ranges

Type
GIT
Repo
https://github.com/google/exposure-notifications-verification-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1
v0.11.0
v0.11.1
v0.12.0
v0.12.1
v0.13.0
v0.14.0
v0.15.0
v0.15.1
v0.16.0
v0.17.0
v0.17.1
v0.18.0
v0.18.1
v0.19.1
v0.19.2
v0.2.0
v0.20.0
v0.21.0
v0.21.1
v0.21.2
v0.22.0
v0.22.1
v0.22.2
v0.23.0
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.28.0
v0.29.0
v0.3.0
v0.30.0
v0.31.0
v0.32.0
v0.33.0
v0.33.1
v0.34.0
v0.34.1
v0.34.2
v0.35.0
v0.35.1
v0.35.2
v0.36.0
v0.37.0
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.7.0
v0.8.0
v0.9.0

v1.*

v1.0.0
v1.1.0
v1.1.1