HIGH🇬🇧 English

CVE-2021-21400

CVSS 7.1v3.1pub. 2021-04-02upd. 2024-11-21

wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock passphrase, the typed passphrase will be sent into the most recently used chat when the user does not actively give focus to the input field. Input element focus is enforced programatically in version 2021-03-15-production.0.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
  • Wire Webapp

    APP
    Wire
    2019-02-112019-02-132019-02-182019-02-272019-02-282019-03-052019-03-072019-03-112019-03-132019-03-202019-03-252019-03-282019-04-082019-04-112019-04-18+ 85 więcej
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2022-29168CRITICAL9.6PL ✓ten sam produkt

XSS w Wire-Webapp — wykonanie kodu przez złośliwe wzmianki @mentions

CVE-2022-24799CRITICAL9.6PL ✓ten sam produkt

XSS w Wire-Webapp — wstrzyknięcie kodu przez podświetlanie składni Markdown

CVE-2021-32683HIGH8.8ten sam produkt

wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists ...

CVE-2025-48066MEDIUM6.0ten sam produkt

wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression c...

CVE-2022-39380MEDIUM5.3ten sam produkt

Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of ...