HIGH🇵🇱 Wersja polska

CVE-2021-21400

CVSS 7.1v3.1pub. 2021-04-02upd. 2024-11-21

wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock passphrase, the typed passphrase will be sent into the most recently used chat when the user does not actively give focus to the input field. Input element focus is enforced programatically in version 2021-03-15-production.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
  • Wire Webapp

    APP
    Wire
    2019-02-112019-02-132019-02-182019-02-272019-02-282019-03-052019-03-072019-03-112019-03-132019-03-202019-03-252019-03-282019-04-082019-04-112019-04-18+ 85 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-29168CRITICAL9.6PL ✓same product

XSS w Wire-Webapp — wykonanie kodu przez złośliwe wzmianki @mentions

CVE-2022-24799CRITICAL9.6PL ✓same product

XSS w Wire-Webapp — wstrzyknięcie kodu przez podświetlanie składni Markdown

CVE-2021-32683HIGH8.8same product

wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists ...

CVE-2025-48066MEDIUM6.0same product

wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression c...

CVE-2022-39380MEDIUM5.3same product

Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of ...