PT-2021-15131 · Google · Google Exposure Notification Verification Server

Michael Mazzolini

·

Published

2021-03-31

·

Updated

2024-08-21

·

CVE-2021-22538

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Exposure Notification Verification Server versions prior to 0.23.1
Description A privilege escalation issue allows an attacker with UserWrite permissions, using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs due to insufficient checks on the allowed set of permissions. The new user creation event would be captured in the Event Log.
Recommendations For versions prior to 0.23.1, update to version 0.23.1 or 0.24.0 to resolve the issue. As a temporary workaround for users who are unable to upgrade, audit users who have UserWrite permissions and regularly review the Event Log for malicious activity.

Fix

Incorrect Default Permissions

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22538
GHSA-5V95-V8C8-3RH6
GO-2022-0798

Affected Products

Google Exposure Notification Verification Server