MEDIUM🇵🇱 Wersja polska

CVE-2021-41119

CVSS 5.3v3.1pub. 2022-04-13upd. 2024-11-21

Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial of service attack via a crafted object causing a hash collision. This collision causes the server to spend at least quadratic time parsing it which can lead to a denial of service for a heavily used server. The issue has been fixed in wire-server 2022-03-01 and is already deployed on all Wire managed services. On premise instances of wire-server need to be updated to 2022-03-01, so that their backends are no longer affected. There are no known workarounds for this issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • Wire Server

    APP
    Wire
    < 2022-03-01
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2022-23610CRITICAL9.1PL ✓same product

Wire Server: bypass SAML SSO przez fałszywe podpisy DSA

CVE-2021-41100HIGH7.4same product

Wire-server is the backing server for the open source wire secure messaging application. In affected versions ...

CVE-2022-31122CRITICAL9.8PL ✓same vendor

Wire Server: Token Recipient Confusion umożliwia pominięcie uwierzytelnienia SAML

CVE-2022-29168CRITICAL9.6PL ✓same vendor

XSS w Wire-Webapp — wykonanie kodu przez złośliwe wzmianki @mentions

CVE-2022-24799CRITICAL9.6PL ✓same vendor

XSS w Wire-Webapp — wstrzyknięcie kodu przez podświetlanie składni Markdown