Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zlatinb

#39644of 53,632
6.8Total CVSS
Vulnerabilities · 1
PT-2021-19904
6.8
2021-07-15
Muwire · Muwire · CVE-2021-32750
**Name of the Vulnerable Software and Affected Versions** MuWire versions prior to 0.8.8 **Description** The issue allows an attacker to de-anonymize users of the MuWire desktop client by sending a message with a subject line containing a URL with an HTML image tag. When the MuWire client attempts to fetch the image via clearnet, it exposes the user's IP address. **Recommendations** For versions prior to 0.8.8, update to MuWire 0.8.8 to resolve the issue. As a temporary workaround, consider disabling the messaging functionality to prevent other users from sending malicious messages.