CVE Published: 09/12/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2021 Source: Google |
Vendor: Google LLC |
Product: Google Exposure-notifications-verification-server Status : PUBLISHED
CVE-2021-22565 Description
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L